Junglewise Threat Intelligence

CVE-2026-44810: Microsoft Windows privilege escalation in Cryptographic Services

CVE-2026-44810 · Severity: high · CVSS 8.4 · Published 2026-06-09

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Windows Cryptographic Services, the component responsible for handling digital certificates and encryption tasks. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could lead to the theft of sensitive data, installation of malicious software, or complete disruption of the affected device.

Technical details

A privilege escalation vulnerability exists in Microsoft Windows Cryptographic Services due to improper authentication (CWE-287). The flaw allows a local attacker to bypass authentication checks within the cryptographic service provider. By successfully exploiting this vulnerability, an attacker with low-privileged access can elevate their permissions to SYSTEM level. The attack requires local access but no prior administrative privileges or user interaction. Microsoft has released security updates to address this issue via the MSRC update guide.

Affected products

  • Microsoft Windows

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References