CVE-2026-21508
HIGHWindows 10/11 Privilege Escalation via Untrusted Search Path
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2026-21508. PoCs published by 0xc4r, XZ1r0.
AI-analyzed exploit summary This PoC demonstrates a DLL hijacking vulnerability (CVE-2026-21508) in Windows 11, where a malicious DLL is loaded by `WUDFHost.exe` to escalate privileges and spawn an elevated `cmd.exe` in session 0. The exploit requires a USB flash drive with a `.jpg` file and triggers via Windows Media Player.
Description
Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.
Exploits (2)
This PoC demonstrates a DLL hijacking vulnerability (CVE-2026-21508) in Windows 11, where a malicious DLL is loaded by `WUDFHost.exe` to escalate privileges and spawn an elevated `cmd.exe` in session 0. The exploit requires a USB flash drive with a `.jpg` file and triggers via Windows Media Player.
This repository contains a functional proof-of-concept exploit for CVE-2026-21508, demonstrating a DLL hijacking attack against WUDFHost.exe. The exploit includes a malicious DLL and a setup script to trigger the vulnerability, resulting in elevated command execution.
References (1)
Scores
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H