ZDI-26-539: (Pwn2Own) Microsoft Windows ipt.sys Incorrect Permission Assignment Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-65773.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-539?
ZDI-26-539 has been assigned a CVSS rating of 7.8, indicating a high severity level.
How do I fix ZDI-26-539?
To fix ZDI-26-539, ensure you apply the latest security updates from Microsoft for the affected Windows installations.
What type of vulnerability is ZDI-26-539?
ZDI-26-539 is a local privilege escalation vulnerability related to incorrect permission assignments in the ipt.sys component of Microsoft Windows.
Who can exploit ZDI-26-539?
ZDI-26-539 can be exploited by local attackers who have the ability to run low-privileged code on the affected system.
What are the impacts of ZDI-26-539?
Successful exploitation of ZDI-26-539 allows an attacker to escalate their privileges to administrative levels on the target Microsoft Windows system.