CVE-2026-36213
HIGHMicrovirt MEmu Android Emulator 9.2.7.0 - Privilege Escalation via MemuService.exe
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2026-36213. PoCs published by sec-zone.
AI-analyzed exploit summary The repository provides a functional proof-of-concept for CVE-2026-36213, a local privilege escalation vulnerability in MEmu Android Emulator 9.2.7.0. The exploit leverages insecure NTFS permissions on the MEmuService.exe binary, allowing any local user to replace it with a malicious executable and gain SYSTEM privileges upon service restart.
Description
An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.exe component.
Exploits (1)
The repository provides a functional proof-of-concept for CVE-2026-36213, a local privilege escalation vulnerability in MEmu Android Emulator 9.2.7.0. The exploit leverages insecure NTFS permissions on the MEmuService.exe binary, allowing any local user to replace it with a malicious executable and gain SYSTEM privileges upon service restart.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H