ZeroHour

CVE-2026-83942

mass

Missing Authorization in Windows Kernel Allows Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p12
Published
()
Modified
AI analysis

CVE-2026-83942 is a missing authorization flaw (CWE-862) in the Microsoft Windows Kernel: a kernel operation fails to verify that the caller holds the required permissions. It is triggered by an authorized local attacker — someone who can already execute low-privileged code on the machine — who exploits the missing check with no user interaction or network access required. Successful exploitation lets the attacker elevate privileges locally, yielding high impact on confidentiality, integrity and availability, consistent with elevation to a kernel/SYSTEM-level context and full control of the host. Any Windows system running an affected kernel version is exposed, although the affected Windows versions are not enumerated in the available data. There is currently no known in-the-wild exploitation, no public proof of concept, and EPSS estimates only a 0.2% probability of exploitation within 30 days.

What to do: Monitor the Microsoft Security Response Center advisory for CVE-2026-83942 and deploy the fix via Windows Update as soon as Microsoft publishes it, since affected builds are not yet enumerated in the available data. Until patched, restrict interactive logon and code-execution rights on shared or multi-user systems to trusted users, and review endpoint telemetry for unexpected privilege-elevation or token-manipulation activity. Because this is a local privilege escalation that requires an attacker to already run code on the machine, prioritize patching endpoints where untrusted users or third-party software regularly execute.

Affected
Microsoft Windows (Windows Kernel)
Estimated exposure
masspotentially hundreds of millions to over 1 billion Windows devices (global Windows installed base) — Windows runs on roughly 1.4 billion active devices worldwide and this flaw resides in the shared kernel, so the plausible affected population is a large share of the installed base, pending Microsoft's affected-version list.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-862
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.