Junglewise Threat Intelligence

CVE-2026-77892: Microsoft Windows Boot Manager privilege escalation via physical attack

CVE-2026-77892 · Severity: medium · CVSS 6.8 · Published 2026-09-08

Executive brief

Windows Boot Manager is the system component responsible for loading the Windows operating system during startup. This vulnerability allows an attacker with physical access to a computer to bypass security restrictions and gain elevated administrative privileges, potentially compromising the entire system.

Technical details

A privilege escalation vulnerability exists in Windows Boot Manager that can be exploited via physical attack vector. The vulnerability allows an unauthorized attacker to escalate privileges on affected systems. Physical access to the machine is required to exploit this issue. While the exact attack mechanism is not detailed in available references, the exposure of Boot Manager internals at a critical stage of system startup creates opportunities for privilege escalation. Microsoft has assigned CVE-2026-77892 to track this issue.

Affected products

  • Microsoft Windows Boot Manager

Timeline

  • 2026-09-08: disclosed

References

Related threats