CVE-2026-58611: Xbox Gaming Services Elevation of Privilege Vulnerability
Published Sep 8, 2026
·Updated
Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.
Other sources
Xbox Gaming Services Elevation of Privilege Vulnerability
— Microsoft
Affected Software
1 affected componentFixes available
Microsoft Xbox Gaming Services<37.114.10001.0
37.114.10001.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 37.114.10001.0
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:14 PM
Data Sourced
via MITRE·05:14 PM
DescriptionSeverity
Frequently Asked Questions
1
Who can exploit this vulnerability?
An attacker must already be authorized on the affected system and have local access. The issue enables elevation of privileges locally; the provided data does not indicate that it is remotely exploitable.
2
What is the potential impact after exploitation?
Successful exploitation can allow an authorized local attacker to elevate privileges. The supplied severity vector indicates high potential impact to confidentiality, integrity, and availability.