Elevation of Privilege Vulnerability in Windows NT OS Kernel by Microsoft
CVE-2026-42980
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 9 June 2026
Badges
What is CVE-2026-42980?
CVE-2026-42980 is a serious vulnerability found in the Windows NT operating system kernel developed by Microsoft. This flaw is categorized as an elevation of privilege vulnerability, specifically arising from an integer underflow, which means that an authorized attacker could exploit it to gain elevated privileges on the local system. This weakness in the kernel can potentially allow a regular user with limited access rights to execute code and operate with enhanced permissions, enabling them to perform unauthorized actions that could compromise the integrity and security of the operating system. Such an exploitation could lead to significant internal threats, including unauthorized data manipulation, injection of malicious software, or disruption of critical system processes.
Potential Impact of CVE-2026-42980
-
Unauthorized Access and Control: Successful exploitation of this vulnerability would grant attackers elevated privileges, allowing them to execute commands and run applications with administrative rights, which could lead to unauthorized access to sensitive data and system resources.
-
System Integrity Compromise: With elevated privileges, an attacker could alter system configurations or install malicious software, potentially leading to a complete system takeover. This could affect the stability and reliability of the operating system, and compromise the overall security posture of the entire network.
-
Increased Risk of Data Breaches: By exploiting this vulnerability, an attacker could access privileged data and potentially exfiltrate sensitive information. This could have severe ramifications for organizations, resulting in data leaks and regulatory penalties, as well as damage to reputation and customer trust.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9234
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8880
Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7417
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Public PoC Released for Windows NT OS Kernel Privilege Escalation Vulnerability
Public PoC exploit code released for a Windows NT OS Kernel local privilege escalation vulnerability caused by an integer underflow in kernel‑mode code.
5 days ago

References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 📰
First article discovered by Cybersecuritynews
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved