Executive brief
Microsoft PowerToys, a suite of system utilities for power users, contains a security flaw that allows a user already logged into a computer to gain higher-level system permissions. This could allow an attacker with limited access to take full control of the device, bypass security restrictions, or access sensitive data. The vulnerability requires the attacker to have an existing account on the machine but does not require any interaction from the victim.
Technical details
A local privilege escalation vulnerability exists in Microsoft PowerToys due to improper authorization (CWE-285). An attacker with low-privileged local access can exploit this flaw to gain elevated system permissions without requiring user interaction. The vulnerability has a CVSS 3.1 base score of 7.8, reflecting high impact on confidentiality, integrity, and availability. Users are advised to refer to the Microsoft Security Response Center (MSRC) for official patches and version-specific mitigation guidance.
Affected products
- Microsoft PowerToys
Timeline
- 2026-06-09: advisory: Initial disclosure by Microsoft and NVD publication.