Description
Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability involves improper authorization checks within Xbox Gaming Services that allow a local, authorized user to gain higher privileges on the same system. This is an elevation of privilege flaw, defined by CWE‑285, which can enable the attacker to access or modify data, execute restricted functions, or install additional software, potentially compromising system confidentiality, integrity, and availability. Attackers must already be authenticated or have local access; therefore the threat is confined to local environments rather than remote attacks.

Affected Systems

Microsoft Xbox Gaming Services is affected. No specific version range is supplied, so the risk applies to all releases that have not yet been patched by Microsoft.

Risk and Exploitability

The CVSS score is 7.8, indicating a high severity local privilege escalation. The EPSS score is not available, so the current exploitation likelihood cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting it may not yet have documented exploits in the wild. The likely attack vector involves a local user who is able to use the Xbox Gaming Services platform to bypass authorization controls and elevate their privileges.

Generated by OpenCVE AI on September 8, 2026 at 18:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the official Microsoft patch for Xbox Gaming Services once released.
  • Enforce strict access controls and least‑privilege policies so that only necessary accounts can access Xbox Gaming Services features.
  • Monitor system logs for unusual privilege‑change events and perform regular audits of user privileges.

Generated by OpenCVE AI on September 8, 2026 at 18:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.
Title Xbox Gaming Services Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft xbox Gaming Services
Weaknesses CWE-285
CPEs cpe:2.3:a:microsoft:xbox_gaming_services:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft xbox Gaming Services
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Xbox Gaming Services
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T18:34:31.131Z

Reserved: 2026-07-01T18:03:43.125Z

Link: CVE-2026-58611

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:17:44.063

Modified: 2026-09-08T18:39:13.460

Link: CVE-2026-58611

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T19:00:13Z

Weaknesses