CVE-2026-42980

HIGH

Microsoft Windows 10 Version 1607 - NT OS Kernel Elevation of Privilege Vulnerability

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-42980. PoCs published by G4sp4rCS.

AI-analyzed exploit summary This repository contains a functional local privilege escalation (LPE) exploit for CVE-2026-42980, a Windows kernel vulnerability in the WMI subsystem. The exploit leverages an integer underflow in `nt!WmipQuerySingleMultiple` (IOCTL 0x228130) to achieve out-of-bounds writes, enabling arbitrary kernel memory manipulation and ultimately SYSTEM privileges.

Description

Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

Exploits (1)

github WORKING POC 1 stars
by G4sp4rCS · cpoc
https://github.com/G4sp4rCS/CVE-2026-42980-POC

This repository contains a functional local privilege escalation (LPE) exploit for CVE-2026-42980, a Windows kernel vulnerability in the WMI subsystem. The exploit leverages an integer underflow in `nt!WmipQuerySingleMultiple` (IOCTL 0x228130) to achieve out-of-bounds writes, enabling arbitrary kernel memory manipulation and ultimately SYSTEM privileges.

Classification
Working Poc 98%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Windows NT OS Kernel (ntoskrnl.exe), WMI subsystem (affected versions up to 2026)
Auth required
Prerequisites: Low-privilege access to the target system · Windows build vulnerable to CVE-2026-42980 (kernel versions with unpatched WMI subsystem) · MSVC x64 toolchain for compilation
mistral-large-3 · analyzed Jul 07, 2026 Full analysis →

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
NT OS Kernel Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42980

Scores

CVSS v3 7.8
EPSS 0.0695
EPSS Percentile 93.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-122 CWE-191
Status published
Products (34)
Microsoft/Windows 10 Version 1607 10.0.14393.0 - 10.0.14393.9234
Microsoft/Windows 10 Version 1809 10.0.17763.0 - 10.0.17763.8880
Microsoft/Windows 10 Version 21H2 10.0.19044.0 - 10.0.19044.7417
Microsoft/Windows 10 Version 22H2 10.0.19045.0 - 10.0.19045.7417
Microsoft/Windows 11 version 23H2 10.0.22631.0 - 10.0.22631.7219
Microsoft/Windows 11 Version 24H2 10.0.26100.0 - 10.0.26100.8655
Microsoft/Windows 11 Version 25H2 10.0.26200.0 - 10.0.26200.8655
Microsoft/Windows 11 Version 26H1 1.0.0 - 10.0.28000.2269
Microsoft/Windows 11 version 26H1 10.0.28000.0 - 10.0.28000.2269
Microsoft/Windows Server 2012 6.2.9200.0 - 6.2.9200.26132
... and 24 more
Published Jun 09, 2026
Tracked Since Jun 09, 2026