CVE-2026-50343
HIGHMicrosoft Install Service Elevation of Privilege Vulnerability
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-50343. PoCs published by Rat5ak.
AI-analyzed exploit summary This repository contains a functional privilege escalation exploit for CVE-2026-50343, leveraging improper registry ACLs on the Microsoft Store InstallService to achieve arbitrary code execution as NT AUTHORITY\SYSTEM from a standard user account. The exploit writes a malicious DLL path to writable registry keys and triggers the service to load it.
Description
Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.
Exploits (1)
This repository contains a functional privilege escalation exploit for CVE-2026-50343, leveraging improper registry ACLs on the Microsoft Store InstallService to achieve arbitrary code execution as NT AUTHORITY\SYSTEM from a standard user account. The exploit writes a malicious DLL path to writable registry keys and triggers the service to load it.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H