CVE-2026-44810
HIGH WAF: Low
CVSS 7.8
Published: 2026-06-09
CWE-287
Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally.
WAF Coverage Analysis
Improper Authentication
Low WAF Coverage
OWASP: A07:2021 Identification and Authentication Failures
Affected Software
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows_11_23h2 | up to 10.0.22631.7219 |
| microsoft | windows_11_23h2 | up to 10.0.22631.7219 |
| microsoft | windows_11_24h2 | up to 10.0.26100.8655 |
| microsoft | windows_11_24h2 | up to 10.0.26100.8655 |
| microsoft | windows_11_25h2 | up to 10.0.26200.8655 |
| microsoft | windows_11_25h2 | up to 10.0.26200.8655 |
| microsoft | windows_11_26h1 | up to 10.0.28000.2269 |
| microsoft | windows_11_26h1 | up to 10.0.28000.2269 |
| microsoft | windows_server_2022 | up to 10.0.20348.5256 |
| microsoft | windows_server_2025 | up to 10.0.26100.32995 |
References
- msrc.microsoft.com (Vendor Advisory)