7.8

CVE-2026-57088

Extensible Storage Engine (ESENT) Elevation of Privilege Vulnerability

Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftWindows 10 1809 HwPlatformx64 Version < 10.0.17763.9020
MicrosoftWindows 10 1809 HwPlatformx86 Version < 10.0.17763.9020
MicrosoftWindows Server 2019 SwEdition- HwPlatformx64 Version < 10.0.17763.9020
MicrosoftWindows Server 2022 HwPlatformx64 Version < 10.0.20348.5386
MicrosoftWindows Server 2025 HwPlatformx64 Version < 10.0.26100.33158
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.198
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Microsoft 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57088
Patch
Vendor Advisory