7.8
CVE-2026-44810
- EPSS 0.26%
- Veröffentlicht 09.06.2026 17:17:17
- Zuletzt bearbeitet 23.07.2026 08:10:00
- Erkennungen
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 11 23h2 HwPlatform arm64 Version < 10.0.22631.7219
Microsoft ≫ Windows 11 23h2 HwPlatform x64 Version < 10.0.22631.7219
Microsoft ≫ Windows 11 24h2 HwPlatform arm64 Version < 10.0.26100.8655
Microsoft ≫ Windows 11 24h2 HwPlatform x64 Version < 10.0.26100.8655
Microsoft ≫ Windows 11 25h2 HwPlatform arm64 Version < 10.0.26200.8655
Microsoft ≫ Windows 11 25h2 HwPlatform x64 Version < 10.0.26200.8655
Microsoft ≫ Windows 11 26h1 HwPlatform arm64 Version < 10.0.28000.2269
Microsoft ≫ Windows 11 26h1 HwPlatform x64 Version < 10.0.28000.2269
Microsoft ≫ Windows Server 2022 Version < 10.0.20348.5256
Microsoft ≫ Windows Server 2025 HwPlatform x64 Version < 10.0.26100.32995
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.172 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| Microsoft | 8.4 | 2.5 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44810