CVE-2026-42980
HIGHMicrosoft Windows 10 Version 1607 - NT OS Kernel Elevation of Privilege Vulnerability
Title source: ruleExploitation Summary
EIP tracks 1 public exploit for CVE-2026-42980. PoCs published by G4sp4rCS.
AI-analyzed exploit summary This repository contains a functional local privilege escalation (LPE) exploit for CVE-2026-42980, a Windows kernel vulnerability in the WMI subsystem. The exploit leverages an integer underflow in `nt!WmipQuerySingleMultiple` (IOCTL 0x228130) to achieve out-of-bounds writes, enabling arbitrary kernel memory manipulation and ultimately SYSTEM privileges.
Description
Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.
Exploits (1)
This repository contains a functional local privilege escalation (LPE) exploit for CVE-2026-42980, a Windows kernel vulnerability in the WMI subsystem. The exploit leverages an integer underflow in `nt!WmipQuerySingleMultiple` (IOCTL 0x228130) to achieve out-of-bounds writes, enabling arbitrary kernel memory manipulation and ultimately SYSTEM privileges.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H