Description
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.
Published: 2026-08-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Execution with unnecessary privileges in the Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network. The flaw is a classic privilege‑elevation vulnerability (CWE‑250) that could enable a malicious user to gain higher rights than intended.

Affected Systems

Microsoft Windows App Client for Windows Desktop – the HPC Pack component. No specific product or version numbers are provided in the advisory, so any installation of the HPC Pack on Windows Desktop is potentially affected.

Risk and Exploitability

The vulnerability has a CVSS score of 8.8, classifying it as high severity. EPSS is not available, and it is not listed in CISA’s KEV catalog, but the high CVSS indicates a serious risk. The likely attack vector is remote or network‑based, requiring an attacker with already authorized access to the HPC service to expand their privileges. Because the flaw permits elevation over a network, attackers can affect multiple users or systems if the HPC Pack is exposed to untrusted hosts.

Generated by OpenCVE AI on August 12, 2026 at 17:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Microsoft patches or updates for the HPC Pack component as soon as they are released.
  • Restrict network access to the HPC service, allowing connections only from trusted hosts or networks.
  • Monitor system logs for abnormal privilege changes or unauthorized activity, and investigate any such events promptly.

Generated by OpenCVE AI on August 12, 2026 at 17:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Hpc Pack 2019
CPEs cpe:2.3:a:microsoft:windows_app_client_for_windows_desktop:*:*:*:*:*:windows:*:* cpe:2.3:a:microsoft:microsoft_hpc_pack_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft microsoft Hpc Pack 2019

Thu, 13 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows App
CPEs cpe:2.3:a:microsoft:windows_app:*:*:*:*:*:windows:*:*
Vendors & Products Microsoft windows App

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.
Title Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows App Client For Windows Desktop
Weaknesses CWE-250
CPEs cpe:2.3:a:microsoft:windows_app_client_for_windows_desktop:*:*:*:*:*:windows:*:*
Vendors & Products Microsoft
Microsoft windows App Client For Windows Desktop
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Hpc Pack 2019 Windows App Windows App Client For Windows Desktop
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:04:30.360Z

Reserved: 2026-07-02T16:05:24.070Z

Link: CVE-2026-59133

cve-icon Vulnrichment

Updated: 2026-08-11T18:27:44.599Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:07.610

Modified: 2026-08-28T20:18:53.110

Link: CVE-2026-59133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T17:30:06Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges