CVE-2026-36213

HIGH

Microvirt MEmu Android Emulator 9.2.7.0 - Privilege Escalation via MemuService.exe

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-36213. PoCs published by sec-zone.

AI-analyzed exploit summary The repository provides a functional proof-of-concept for CVE-2026-36213, a local privilege escalation vulnerability in MEmu Android Emulator 9.2.7.0. The exploit leverages insecure NTFS permissions on the MEmuService.exe binary, allowing any local user to replace it with a malicious executable and gain SYSTEM privileges upon service restart.

Description

An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.exe component.

Exploits (1)

nomisec WORKING POC
by sec-zone · poc
https://github.com/sec-zone/CVE-2026-36213

The repository provides a functional proof-of-concept for CVE-2026-36213, a local privilege escalation vulnerability in MEmu Android Emulator 9.2.7.0. The exploit leverages insecure NTFS permissions on the MEmuService.exe binary, allowing any local user to replace it with a malicious executable and gain SYSTEM privileges upon service restart.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: MEmu Android Emulator 9.2.7.0 and earlier
Auth required
Prerequisites: Local user access · MEmu Android Emulator 9.2.7.0 or earlier installed
devstral-2 · analyzed Jun 17, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 3.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Published Jun 15, 2026
Tracked Since Jun 16, 2026