Description
Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability stems from an untrusted pointer dereference in Windows Secure Kernel Mode. An attacker with some level of system access can exploit this flaw to gain elevated local privileges, potentially allowing full control over the affected machine. The weakness corresponds to CWE-822, which involves failures in handling untrusted input.

Affected Systems

The flaw affects Microsoft Windows 11 version 26H1 on x64 architecture. No other vendor or product is listed as affected at this time.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity. With no EPSS value available and the vulnerability not listed in CISA KEV, the overall risk remains high yet lacks publicly confirmed exploitation data. The likely attack vector is local, requiring the attacker to already have authenticated access to the system to reach the vulnerable code.

Generated by OpenCVE AI on September 9, 2026 at 03:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Microsoft security update for Windows 11 version 26H1 (see the Microsoft Update Guide link).
  • Reboot the system after the update to ensure the new kernel image is loaded.
  • Restrict local administrative privileges to trusted users only until the patch can be applied, thereby limiting the attack surface for potential exploitation.

Generated by OpenCVE AI on September 9, 2026 at 03:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 26h1
CPEs cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 11 26h1

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Title Windows Secure Kernel Mode Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 26h1
Weaknesses CWE-822
CPEs cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 26h1 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:57.778Z

Reserved: 2026-08-31T23:40:59.640Z

Link: CVE-2026-83939

cve-icon Vulnrichment

Updated: 2026-09-09T09:52:11.015Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:21:04.570

Modified: 2026-09-10T15:00:33.013

Link: CVE-2026-83939

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:45:17Z

Weaknesses
  • CWE-822

    Untrusted Pointer Dereference