CVE-2026-21508

HIGH

Windows 10/11 Privilege Escalation via Untrusted Search Path

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2026-21508. PoCs published by 0xc4r, XZ1r0.

AI-analyzed exploit summary This PoC demonstrates a DLL hijacking vulnerability (CVE-2026-21508) in Windows 11, where a malicious DLL is loaded by `WUDFHost.exe` to escalate privileges and spawn an elevated `cmd.exe` in session 0. The exploit requires a USB flash drive with a `.jpg` file and triggers via Windows Media Player.

Description

Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.

Exploits (2)

nomisec WORKING POC 17 stars
by 0xc4r · poc
https://github.com/0xc4r/CVE-2026-21508_POC

This PoC demonstrates a DLL hijacking vulnerability (CVE-2026-21508) in Windows 11, where a malicious DLL is loaded by `WUDFHost.exe` to escalate privileges and spawn an elevated `cmd.exe` in session 0. The exploit requires a USB flash drive with a `.jpg` file and triggers via Windows Media Player.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Windows 11 (WUDFHost.exe)
No auth needed
Prerequisites: Windows 11 environment · USB flash drive with `.jpg` file · Windows Media Player configured
devstral-2 · analyzed Feb 16, 2026 Full analysis →
github WORKING POC
by XZ1r0 · pythonpoc
https://github.com/XZ1r0/cve-2026-poc-collection/tree/main/other/CVE-2026-21508_POC

This repository contains a functional proof-of-concept exploit for CVE-2026-21508, demonstrating a DLL hijacking attack against WUDFHost.exe. The exploit includes a malicious DLL and a setup script to trigger the vulnerability, resulting in elevated command execution.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Windows 11 (WUDFHost.exe)
No auth needed
Prerequisites: USB flash drive with .jpg file · Windows Media Player configured
devstral-2 · analyzed May 21, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 7.0
EPSS 0.0007
EPSS Percentile 22.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-426 CWE-287
Status published
Products (36)
Microsoft/Windows 10 Version 1607 10.0.14393.0 - 10.0.14393.8868
Microsoft/Windows 10 Version 1809 10.0.17763.0 - 10.0.17763.8389
Microsoft/Windows 10 Version 21H2 10.0.19044.0 - 10.0.19044.6937
Microsoft/Windows 10 Version 22H2 10.0.19045.0 - 10.0.19045.6937
Microsoft/Windows 11 version 22H3 10.0.22631.0 - 10.0.22631.6649
Microsoft/Windows 11 Version 23H2 10.0.22631.0 - 10.0.22631.6649
Microsoft/Windows 11 Version 24H2 10.0.26100.0 - 10.0.26100.7840
Microsoft/Windows 11 Version 25H2 10.0.26200.0 - 10.0.26200.7840
Microsoft/Windows 11 version 26H1 10.0.28000.0 - 10.0.28000.1575
Microsoft/Windows 11 Version 26H1 10.0.28000.0 - 10.0.28000.1575
... and 26 more
Published Feb 10, 2026
Tracked Since Feb 18, 2026