Junglewise Threat Intelligence

CVE-2026-57088: Microsoft ESENT privilege escalation in Windows

CVE-2026-57088 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2025, Microsoft Windows Server 2022, Microsoft Windows 10 Version 1809, Microsoft Windows 10, Microsoft Windows Server 2019. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Microsoft Extensible Storage Engine (ESENT), a component used by Windows to manage data storage for various system functions. An attacker who already has basic access to a computer could exploit this flaw to gain higher-level administrative privileges. This could allow them to take full control of the affected system, access sensitive data, or disrupt operations.

Technical details

A privilege escalation vulnerability exists in the Microsoft Extensible Storage Engine (ESENT) due to improper access control (CWE-284). The vulnerability allows a locally authenticated attacker with low privileges to gain elevated permissions on the host operating system. The attack vector is local, requiring the attacker to execute a specially crafted application on the target system. Successful exploitation grants the attacker high confidentiality, integrity, and availability impacts, effectively allowing full system compromise. Microsoft has released security updates for affected versions of Windows 10, Windows Server 2019, 2022, and 2025.

Affected products

  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows Server 2019 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.5386
  • Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158

Timeline

  • 2026-07-14: advisory: Microsoft published the security advisory.
  • 2026-07-14: disclosed: NVD published the CVE record.

References

Related threats