Junglewise Threat Intelligence

CVE-2026-49161: Microsoft PC Manager improper access control security bypass

CVE-2026-49161 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Microsoft PC Manager. Vendors: Microsoft.

Executive brief

Microsoft PC Manager, a tool used for system maintenance and performance optimization, contains a security flaw that allows an authorized user to bypass built-in security protections. An attacker who already has basic access to a computer could exploit this to gain higher-level permissions or access restricted data. This could lead to a full compromise of the affected system, impacting the confidentiality and integrity of user information.

Technical details

A vulnerability classified as improper access control (CWE-284) exists in Microsoft PC Manager. The flaw allows a locally authenticated attacker with low privileges to bypass security restrictions due to insufficient validation of access rights within the application. By exploiting this, an attacker can achieve elevated privileges, potentially leading to a complete compromise of the system's confidentiality, integrity, and availability. The attack requires local access to the machine but does not require user interaction. Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft PC Manager

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: NVD and MSRC advisory published

References

Related threats