Skip to content
Auto-CTI
Back to today
MEDIUM B2

ZDI-26-445: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability

B ZDI: Published Advisories · · CVE-2026-50325

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

CVSS
7.0
EPSS
0%

Affected versions

windows 10 1607 windows 10 1809 windows 10 21h2

Key insight

Local privilege escalation vulnerability in Windows WMI requires initial code execution, affects all Windows Server versions in the IT infrastructure.

Description

The CVE-2026-50325 vulnerability in Windows WMI Providers allows attackers with low privileges to escalate privileges on affected Windows installations. An attacker must first obtain the ability to execute low-privileged code on the target system. With a CVSS score of 7.0, this is a significant local escalation risk. The vulnerability affects Windows Server environments and requires timely patch management.

Risk score

51
cvss base
70.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
85.00
industry weight
1.21
freshness factor
0.50
exploitability factor
1.00
days old
49.00
vendor mismatch penalty
0.00

Path: operational

MITRE ATT&CK mapping

3 TTPs
Recon
Resource Dev
Initial Access
Execution
Persistence
Def. Evasion
Cred. Access
Discovery
Lateral Mov.
Collection
C2
Exfiltration
Impact
Conf.: high medium low

Procedure details

Technique Tactic Procedure Conf. Source
T1078.003
Local Accounts
Privilege Escalation Attacker leverages CVE-2026-50325 incorrect authorization in Microsoft Windows WMI Providers to escalate privileges from a low-privileged local account to higher privileges on the target system high llm
T1546.003
Windows Management Instrumentation Event Subscription
Privilege Escalation The vulnerability exists within Microsoft Windows WMI Providers, where incorrect authorization checks allow local attackers to abuse WMI provider functionality to escalate privileges high llm
T1068
Exploitation for Privilege Escalation
Privilege Escalation CVE-2026-50325 is exploited by a local attacker with low-privileged code execution to escalate privileges on affected Microsoft Windows installations via incorrect authorization in WMI Providers high llm
ESC