Junglewise Threat Intelligence

CVE-2026-33828: Microsoft Windows trust boundary violation in Windows Attestation

CVE-2026-33828 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Attestation service, which is responsible for verifying the integrity of a computer's hardware and software state. An attacker who already has basic access to a system could exploit this flaw to gain higher-level administrative permissions. This could allow them to bypass security controls, access sensitive data, or take full control of the affected device.

Technical details

A trust boundary violation (CWE-501) exists within the Windows Attestation component. The vulnerability stems from improper validation or isolation between different privilege levels during attestation processes. An attacker with low-privileged local access can exploit this flaw without any user interaction to gain SYSTEM-level privileges. This allows for complete compromise of the confidentiality, integrity, and availability of the local host. Microsoft has released security updates to address this issue via the MSRC Update Guide.

Affected products

  • Microsoft Windows

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References