CVE-2026-83942
massMissing Authorization in Windows Kernel Allows Local Privilege Escalation
CVE-2026-83942 is a missing authorization flaw (CWE-862) in the Microsoft Windows Kernel: a kernel operation fails to verify that the caller holds the required permissions. It is triggered by an authorized local attacker — someone who can already execute low-privileged code on the machine — who exploits the missing check with no user interaction or network access required. Successful exploitation lets the attacker elevate privileges locally, yielding high impact on confidentiality, integrity and availability, consistent with elevation to a kernel/SYSTEM-level context and full control of the host. Any Windows system running an affected kernel version is exposed, although the affected Windows versions are not enumerated in the available data. There is currently no known in-the-wild exploitation, no public proof of concept, and EPSS estimates only a 0.2% probability of exploitation within 30 days.
What to do: Monitor the Microsoft Security Response Center advisory for CVE-2026-83942 and deploy the fix via Windows Update as soon as Microsoft publishes it, since affected builds are not yet enumerated in the available data. Until patched, restrict interactive logon and code-execution rights on shared or multi-user systems to trusted users, and review endpoint telemetry for unexpected privilege-elevation or token-manipulation activity. Because this is a local privilege escalation that requires an attacker to already run code on the machine, prioritize patching endpoints where untrusted users or third-party software regularly execute.
| Microsoft Windows (Windows Kernel) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.