Junglewise Threat Intelligence

CVE-2026-41092: Microsoft Kinect privilege escalation via improper access control

CVE-2026-41092 · Severity: high · CVSS 7.8 · Published 2026-06-09

Vendors: Microsoft.

Executive brief

A security vulnerability in Microsoft Kinect hardware could allow a user who already has basic access to the system to gain higher-level administrative permissions. This could lead to unauthorized access to sensitive data or the ability to modify system settings. To exploit this, an attacker must have the ability to run code locally on the machine connected to the Kinect sensor.

Technical details

A local privilege escalation vulnerability exists in Microsoft Kinect due to improper access control (CWE-284). An attacker with low-privileged local access can exploit this flaw to gain elevated permissions on the host system. The attack requires local code execution but no user interaction. Successful exploitation grants the attacker high confidentiality, integrity, and availability impacts, effectively allowing full control over the affected environment. Microsoft has released an advisory via the MSRC Update Guide to address this issue.

Affected products

  • Microsoft Kinect

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References