Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-42980 PoC: Windows kernel WMI integer underflow local privilege escalation

Summary

Disclosure repo for CVE-2026-42980: a Windows kernel WMI integer underflow exploited for local privilege escalation to NT AUTHORITY\SYSTEM, with C sources, build scripts and bilingual write-ups.

Why it matters

The public code turns a Windows kernel integer underflow into local escalation from a normal user to SYSTEM, making it relevant to authorized kernel research and patch validation. Reproduction should be limited to owned, isolated, recoverable systems, and Microsoft fixes should be applied promptly.
Vendor
Microsoft
Product
Windows NT OS Kernel / WMI
Affected versions
Microsoft Windows builds affected by the Windows NT OS Kernel WMI integer-underflow vulnerability; consult Microsoft security updates for fixed build details
CVSS
7.8
Published
Collected

original ↗

Related coverage

back