Improper Authentication in Microsoft Authenticator Enables Local Privilege Escalation
AI analysis
CVE-2026-80097 is an improper authentication flaw (CWE-287) in Microsoft Authenticator that allows an unauthorized attacker to elevate privileges locally, rated 8.6 (high) with no privileges required, required user interaction, and a changed scope. Exploitation requires local access to a device running the app plus user interaction, and because the scope is changed, a successful attack crosses a security boundary beyond the Authenticator component itself. A successful exploit yields local privilege elevation with high impact to confidentiality, integrity, and availability. Anyone running affected versions of Microsoft Authenticator is affected; the app is Microsoft's standard multi-factor authentication app for Entra ID/Microsoft 365 and is widely deployed across enterprise and personal mobile devices. As of the September 2026 disclosure it is not known to be exploited - no public PoC, not in CISA KEV, EPSS 0.4% (33rd percentile) - and it was patched amid the record 974-flaw Patch Tuesday, though the two actively exploited zero-days in that release are Windows flaws, not this one.
What to do: Update Microsoft Authenticator through its usual app-store distribution channels (iOS App Store/Google Play) to the build released with September 2026 Patch Tuesday, and verify updated versions across the fleet via MDM or app inventory; specific patched build numbers were not provided in the source data. Prioritize shared workstations, kiosks, and hot-desked or BYOD endpoints where unprivileged local users interact with the app. No public PoC or in-the-wild exploitation is known, so routine prompt patching is appropriate.
Estimated exposure
mass≈100M+ users/devices (Microsoft's standard MFA app, with app-store install counts on the order of hundreds of millions) — Microsoft Authenticator is the default MFA app deployed to Microsoft Entra ID/Microsoft 365 users, and public app-store listings show on the order of 100M+ installs, so the affected install base plausibly reaches the hundreds of millions,…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.