CVE-2026-20508: Microsoft Power HAL vulnerability
In Power HAL, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11165543; Issue ID: MSV-9012.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS11165543 - Compensating control
If a local attacker could obtain System privilege, treat the System account as potentially compromised; restrict local access to privileged components/entry points on affected systems (e.g., limit who/what can obtain System-level privileges) until the patch is applied.
Event History
Frequently Asked Questions
What level of access is required before this issue can be exploited?
The malicious actor must already have System privilege. The issue is described as enabling further local escalation of privilege from that position.
Is user interaction required?
No. Exploitation does not require user interaction.
What identifiers can be used to track the vendor fix?
The listed patch ID is ALPS11165543, and the associated issue ID is MSV-9012.