Improper Authentication in Microsoft Windows Cryptographic Services
CVE-2026-44810

8.4HIGH

What is CVE-2026-44810?

The vulnerability identified in Microsoft Windows Cryptographic Services stems from improper authentication mechanisms. This weakness permits unauthorized attackers to elevate privileges locally, potentially enabling them to execute arbitrary code or access sensitive information on affected systems. It underscores the importance of timely patching and system updates to mitigate risks against such attacks.

Affected Version(s)

Windows 11 version 23H2 ARM64-based Systems 10.0.22631.0 < 10.0.22631.7219

Windows 11 Version 23H2 x64-based Systems 10.0.22631.0 < 10.0.22631.7219

Windows 11 Version 24H2 ARM64-based Systems 10.0.26100.0 < 10.0.26100.8655

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.