ZDI-26-539: (Pwn2Own) Microsoft Windows ipt.sys Incorrect Permission Assignment Local Privilege Escalation Vulnerability
ZDI advisory discloses Windows ipt.sys local privilege escalation (CVE-2026-65773, CVSS 7.8) demonstrated at Pwn2Own.
ZDI advisory ZDI-26-539 describes an incorrect permission assignment flaw in Microsoft Windows ipt.sys, tracked as CVE-2026-65773 with a CVSS score of 7.8. A local attacker who can already execute low-privileged code can exploit it to escalate privileges. The vulnerability was demonstrated at Pwn2Own.
- Local privilege escalation in Microsoft Windows ipt.sys
- CVE-2026-65773, CVSS 7.8, disclosed via Pwn2Own
- Requires attacker to already run low-privileged code
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-65773 | Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. NVD description · AI analysis pending | 7.8 | <1% |
| — |
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-65773.
This source does not provide full text. Read it at zerodayinitiative.com.