ZeroHour
ZDI Published Advisoriespublished ()ingested 1

ZDI-26-539: (Pwn2Own) Microsoft Windows ipt.sys Incorrect Permission Assignment Local Privilege Escalation Vulnerability

mediumAdvisoryimportance 35CVE-2026-65773
AI summary · glm-5.3

ZDI advisory discloses Windows ipt.sys local privilege escalation (CVE-2026-65773, CVSS 7.8) demonstrated at Pwn2Own.

ZDI advisory ZDI-26-539 describes an incorrect permission assignment flaw in Microsoft Windows ipt.sys, tracked as CVE-2026-65773 with a CVSS score of 7.8. A local attacker who can already execute low-privileged code can exploit it to escalate privileges. The vulnerability was demonstrated at Pwn2Own.

  • Local privilege escalation in Microsoft Windows ipt.sys
  • CVE-2026-65773, CVSS 7.8, disclosed via Pwn2Own
  • Requires attacker to already run low-privileged code

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-65773
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.

Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.

NVD description · AI analysis pending
7.8<1%
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • microsoft windows 10 22h2
  • +1 more
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-65773.

This source does not provide full text. Read it at zerodayinitiative.com.