Security Feature Bypass in Microsoft Edge by Elevation of Privileges
CVE-2026-21223

5.1MEDIUM

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
16 January 2026

What is CVE-2026-21223?

A vulnerability in Microsoft Edge allows non-administrator local users to execute privileged update commands through the IElevatorEdge interface. By invoking the LaunchUpdateCmdElevatedAndWait method, these users can alter critical system registry settings related to Windows Virtualization-Based Security (VBS). This manipulation enables them to disable essential protections such as Credential Guard and Hypervisor-protected Code Integrity, thereby bypassing vital security measures designed to safeguard the operating system.

Affected Version(s)

Microsoft Edge (Chromium-based) 1.0.0.0 < 144.0.3719.82

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.