CVE-2026-42980 PoC: Windows kernel WMI integer underflow local privilege escalation
github.com | vulnerability | High | CVE-2026-42980 | #public-poc | #kernel-security | #privilege-escalation | #windows-security | #windows | #wmi | #integer-underflow | #cwe-122 | #cwe-191 | #vulnerability | #poc | #windows-kernel | #cve-2026-42980
Summary
Disclosure repo for CVE-2026-42980: a Windows kernel WMI integer underflow exploited for local privilege escalation to NT AUTHORITY\SYSTEM, with C sources, build scripts and bilingual write-ups.
Why it matters
The public code turns a Windows kernel integer underflow into local escalation from a normal user to SYSTEM, making it relevant to authorized kernel research and patch validation. Reproduction should be limited to owned, isolated, recoverable systems, and Microsoft fixes should be applied promptly.
- Vendor
- Microsoft
- Product
- Windows NT OS Kernel / WMI
- Affected versions
- Microsoft Windows builds affected by the Windows NT OS Kernel WMI integer-underflow vulnerability; consult Microsoft security updates for fixed build details
- CVSS
- 7.8
- Published
- Collected
Skip to content