Skip to content
Auto-CTI
Back to today
NEW MEDIUM B2

ZDI-26-539: (Pwn2Own) Microsoft Windows ipt.sys Incorrect Permission Assignment Local Privilege Escalation Vulnerability

B ZDI: Published Advisories · · CVE-2026-65773

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

CVSS
7.8
EPSS
0%

Affected versions

windows 10 1809 windows 10 21h2 windows 10 22h2

Key insight

The Pwn2Own finding demonstrates exploitability of the local privilege escalation in ipt.sys; active exploitation is not known.

Description

The vulnerability CVE-2026-65773 in Microsoft Windows ipt.sys is due to incorrect permission assignment. A local attacker can escalate privileges on the affected system after executing low-privileged code. ZDI has assigned a CVSS score of 7.8. The finding was demonstrated as part of Pwn2Own, confirming exploitability. Active exploitation in the wild is currently not documented.

Risk score

56
cvss base
78.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
93.00
industry weight
1.21
freshness factor
0.50
exploitability factor
1.00
days old
31.00
vendor mismatch penalty
0.00

Path: operational

MITRE ATT&CK mapping

1 TTP
Recon
Resource Dev
Initial Access
Execution
Persistence
Def. Evasion
Cred. Access
Discovery
Lateral Mov.
Collection
C2
Exfiltration
Impact
Conf.: high medium low

Procedure details

Technique Tactic Procedure Conf. Source
T1068
Exploitation for Privilege Escalation
Privilege Escalation A local attacker who has obtained the ability to execute low-privileged code on a target system exploits an incorrect permission assignment in the Microsoft Windows ipt.sys driver to escalate privileges. high llm
ESC