← Back to CVE search

CVE-2026-49170

Windows StateRepository API

Description

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

CVSS 7.8EPSS 2.7969999999999997%Risk 0.98
View source
Published
2026-07-14 17:16:51
Affected versions
unknown
Type
Operating system
Last modified
2026-07-22 16:17:27
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Operating systems
Windows