Description
Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.
Published: 2026-06-09
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper authorization flaw in Microsoft PowerToys allows an attacker who already holds local user authority to elevate privileges on the same system. The vulnerability is classified as CWE-285 and can result in an attacker gaining higher local privileges, potentially moving from a standard user to an administrator or similar privileged account. The impact is limited to the local system where PowerToys is installed.

Affected Systems

Microsoft PowerToys is the affected product. No specific versions are listed in the data, so any installation of PowerToys should be reviewed for the presence of the fix identified by CVE-2026-42902.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, but the EPSS score is unavailable, so the current exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local: any user who already has access to PowerToys on the system—whether a standard user or a privileged account—could exploit the improper authorization to gain higher local privileges. This inference is based on the description which states the flaw allows an authorized attacker to elevate privileges locally. The data does not mention remote triggers or network exposure, limiting the scope to the machine on which PowerToys is installed.

Generated by OpenCVE AI on June 9, 2026 at 20:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft PowerToys update that contains the fix for CVE-2026-42902, as detailed in the Microsoft Security Response Center advisory.
  • Restrict installation, configuration, and use of PowerToys to trusted administrators or privileged accounts to reduce the opportunity for exploitation.
  • Monitor account activity for signs of unauthorized privilege escalation, ensuring that the patch remains deployed and that users cannot leverage PowerToys to elevate privileges.

Generated by OpenCVE AI on June 9, 2026 at 20:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.
Title Microsoft PowerToys Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft power Toys
Weaknesses CWE-285
CPEs cpe:2.3:a:microsoft:power_toys:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft power Toys
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Power Toys
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-06-09T21:49:47.108Z

Reserved: 2026-04-30T22:35:54.967Z

Link: CVE-2026-42902

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-09T17:17:09.670

Modified: 2026-06-09T19:32:51.440

Link: CVE-2026-42902

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T20:15:07Z

Weaknesses