7.8
CVE-2026-57088
- EPSS 0.28%
- Veröffentlicht 14.07.2026 17:09:35
- Zuletzt bearbeitet 23.07.2026 05:16:37
- CVE-Watchlists
- Unerledigt
Extensible Storage Engine (ESENT) Elevation of Privilege Vulnerability
Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 1809 HwPlatformx64 Version < 10.0.17763.9020
Microsoft ≫ Windows 10 1809 HwPlatformx86 Version < 10.0.17763.9020
Microsoft ≫ Windows Server 2019 SwEdition- HwPlatformx64 Version < 10.0.17763.9020
Microsoft ≫ Windows Server 2022 HwPlatformx64 Version < 10.0.20348.5386
Microsoft ≫ Windows Server 2025 HwPlatformx64 Version < 10.0.26100.33158
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.198 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Microsoft | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57088