Impact
An improper authorization flaw in Microsoft PowerToys allows an attacker who already holds local user authority to elevate privileges on the same system. The vulnerability is classified as CWE-285 and can result in an attacker gaining higher local privileges, potentially moving from a standard user to an administrator or similar privileged account. The impact is limited to the local system where PowerToys is installed.
Affected Systems
Microsoft PowerToys is the affected product. No specific versions are listed in the data, so any installation of PowerToys should be reviewed for the presence of the fix identified by CVE-2026-42902.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score is unavailable, so the current exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local: any user who already has access to PowerToys on the system—whether a standard user or a privileged account—could exploit the improper authorization to gain higher local privileges. This inference is based on the description which states the flaw allows an authorized attacker to elevate privileges locally. The data does not mention remote triggers or network exposure, limiting the scope to the machine on which PowerToys is installed.
OpenCVE Enrichment