ZeroHour

CVE-2026-83498

mass

Untrusted Pointer Dereference in Windows VBS Enclave Allows Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-83498 is an untrusted pointer dereference (CWE-822) in the Virtualization-Based Security (VBS) Enclave component of Microsoft Windows. An authorized local attacker, meaning someone who already holds low-privileged code execution on the machine, can cause the enclave to dereference attacker-controlled pointers with no user interaction required. Successful exploitation breaks the VBS enclave trust boundary and elevates the attacker's privileges locally, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). All Windows editions that ship the VBS Enclave feature are in scope, but the source data does not enumerate specific vulnerable builds, so defenders should consult Microsoft's advisory for the exact affected-product matrix. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, EPSS assigns only a 0.3% probability of exploitation within 30 days, and fixes shipped in Microsoft's September 2026 Patch Tuesday release, which addressed 974 vulnerabilities including 2 zero-days (this CVE is not confirmed to be one of the actively exploited ones).

What to do: Apply Microsoft's September 2026 Patch Tuesday cumulative updates to affected Windows systems, prioritizing multi-user hosts, jump servers, and endpoints where untrusted or low-privileged users can execute code. Verify VBS status via System Information (msinfo32) and confirm the September 2026 update is installed using the fixed-build details in Microsoft's advisory. No workaround is documented, and with no public PoC or in-the-wild exploitation known, routine patch cadence is reasonable for isolated single-user systems.

Affected
Microsoft Windows — Virtualization-Based Security (VBS) Enclave
Estimated exposure
mass≈ hundreds of millions of Windows 10/11 devices ship the vulnerable VBS Enclave component — The Windows 10/11 installed base is in the hundreds of millions and VBS, including enclave support, ships broadly with the OS (enabled by default on most modern Windows 11 hardware), although actual exploitability additionally requires an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2025
Weakness
CWE-822
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday Update September 2026 – 974 Vulnerabilities Fixed, Including 2 Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities across Windows and Office, including two actively exploited Windows privilege-escalation zero-days.

Microsoft's September 2026 Patch Tuesday addresses 974 vulnerabilities spanning Windows, Office, SQL Server, SharePoint, Exchange, Azure, and developer tools. Two Windows zero-days are confirmed exploited in attacks: CVE-2026-85880, a Windows ALPC elevation-of-privilege flaw, and CVE-2026-81963, a Windows Update Stack privilege-escalation flaw involving link following. The release also includes Critical fixes for Windows Secure Kernel Mode, VBS Enclave, Excel, and Word.