CVE-2026-49176
Published Jul 14, 2026
Last updated 5 days ago
AI description
CVE-2026-49176 is a local privilege escalation vulnerability found in the Microsoft Windows WalletService component. This flaw stems from improper privilege management combined with link-following behavior (CWE-59). An authorized local attacker can exploit this vulnerability to gain SYSTEM-level privileges on affected Windows client and server editions. The WalletService, which manages wallet-related objects and credentials, performs privileged file or object operations without adequately validating the identity or trust boundary of resources it interacts with. Because the service operates with elevated rights, a standard local user can influence these operations to act on attacker-controlled paths, often involving symbolic links, junctions, or mount points. Microsoft addressed this issue through its security update guide, and a public proof-of-concept has been published on GitHub.
- Description
- Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2025
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- secure@microsoft.com
- CWE-59
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
9
🚨 A public PoC has been released for CVE-2026-49176, a Windows WalletService privilege escalation vulnerability. Full technical details are now public. Patch affected Windows systems immediately. 🔗 https://t.co/oxhXTMtPEZ #Windows #LPE #CVE #CyberSecurity
@ThreatWire_
27 Jul 2026
4888 Impressions
9 Retweets
50 Likes
23 Bookmarks
0 Replies
0 Quotes
ثغرة تصعيد صلاحيات جديدة في Windows. ثغرة CVE-2026-49176 تستهدف WalletService وقد تتيح الوصول إلى صلاحيات SYSTEM، مع شرح تقني وإثبات مفهوم لمسار الاستغلال. New Windows LPE research worth
@fad_777
22 Jul 2026
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "1A8DB50E-7571-4925-A293-CAB93ECD0EBF",
"versionEndExcluding": "10.0.14393.9339",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "A9DC4EC9-4E72-4CBC-BA0B-39CCC45DB8CE",
"versionEndExcluding": "10.0.14393.9339",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "643F21D8-3A5B-477D-AFFC-2451DDC472CC",
"versionEndExcluding": "10.0.17763.9020",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "A68E51D8-C76C-4C9E-9CBD-C7D4D4BCDFAA",
"versionEndExcluding": "10.0.17763.9020",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "038B4A9C-95B9-440A-83A2-AF10BC24590C",
"versionEndExcluding": "10.0.19044.7548",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "FCA35115-58F4-4015-9CA2-C33F45605AA6",
"versionEndExcluding": "10.0.19044.7548",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "02C2F9D5-439A-45D2-98EB-08DB85673712",
"versionEndExcluding": "10.0.19044.7548",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "80F87C10-5D02-4EC9-B1A4-8FD7F6CFE758",
"versionEndExcluding": "10.0.19045.7548",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "048B08D3-1959-47C0-A592-FCF0DCCD65A4",
"versionEndExcluding": "10.0.19045.7548",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "A41562FD-04BC-4FC3-B847-D87D164A9C15",
"versionEndExcluding": "10.0.19045.7548",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "6D55C01A-5908-4CFC-BEB6-BBF3B6F0C5AF",
"versionEndExcluding": "10.0.26100.8875",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "740B730D-AEC5-4735-A122-B1CF8B3C364C",
"versionEndExcluding": "10.0.26100.8875",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "E26E96B6-1469-46AE-9CB5-AB7A0372C398",
"versionEndExcluding": "10.0.26200.8875",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "DDBCA9E4-7BFB-423A-B7A7-9CBF5625053D",
"versionEndExcluding": "10.0.26200.8875",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "8967AF79-CAD0-4F87-85A5-95D031C9FEFA",
"versionEndExcluding": "10.0.28000.2269",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "8E90830B-0BD1-4D01-9C7D-0F0E1828A0F5",
"versionEndExcluding": "10.0.28000.2525",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
"matchCriteriaId": "34D1270A-7D50-46CC-87EE-0A4E25F9C800",
"versionEndExcluding": "10.0.14393.9339",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D0E1AB94-0B38-4BB7-94EB-988EA266D6D5",
"versionEndExcluding": "10.0.17763.9020",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
"matchCriteriaId": "9E9A0C18-3AD2-4E59-97AF-A2343E466929",
"versionEndExcluding": "10.0.20348.5386",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
"matchCriteriaId": "22BE2FE9-37B9-4FF2-B43A-60A3518E0F08",
"versionEndExcluding": "10.0.26100.33158",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]