Description
Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a buffer over-read in the Windows Subsystem for Linux (WSL2) kernel that an attacker with local, authorized access can exploit to gain elevated privileges. This flaw allows the attacker to read memory beyond intended bounds, potentially leading to unauthorized modification of process memory or privilege escalation. The primary weakness corresponds to CWE-126, a classic out-of-bounds read condition.

Affected Systems

Microsoft Windows Subsystem for Linux (WSL2) is affected. No specific vulnerable version numbers are provided in the advisory, so all installations that use the on any Windows build should be considered at risk until an official fix is released.

Risk and Exploitability

The CVSS score of 7.8 classifies the bug as high severity, while the EPSS score of less than 1 % indicates that large-scale exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a local, authorized user executing code in WSL2. Once a user has local access, they can trigger the buffer over-read to elevate privileges within the Windows host environment.

Generated by OpenCVE AI on July 31, 2026 at 06:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest update for Windows Subsystem for Linux from Microsoft's security advisory.
  • If the update is not yet available, limit local user accounts from running privileged commands inside WSL2 until a resolution is published.
  • Disable or remove WSL2 for users who do not require it and enforce least privilege policies to reduce the attack surface.

Generated by OpenCVE AI on July 31, 2026 at 06:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
Title Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows Subsystem For Linux
Weaknesses CWE-126
CPEs cpe:2.3:a:microsoft:windows_subsystem_for_linux:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows Subsystem For Linux
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows Subsystem For Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:58:07.961Z

Reserved: 2026-06-26T17:45:44.853Z

Link: CVE-2026-57968

cve-icon Vulnrichment

Updated: 2026-07-14T17:52:52.500Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:30:18Z

Weaknesses