Skip to content
Auto-CTI
Back to today
MEDIUM B2

ZDI-26-446: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability

B ZDI: Published Advisories · · CVE-2026-50297

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

CVSS
7.0
EPSS
0%

Affected versions

windows 10 1607 windows 10 1809 windows 10 21h2

Key insight

A local privilege escalation flaw in Windows WMI Providers requires prior code execution access and threatens environments with locally accessible systems.

Description

CVE-2026-50297 is a security flaw in Microsoft Windows WMI Providers that results in local privilege escalation due to improper authorization checks. An attacker with the ability to execute low-privileged code can exploit this vulnerability to obtain higher system privileges. The flaw has been rated CVSS 7.0 and is currently subject to a ZDI advisory. Proof-of-concept or active exploitation is not publicly known at this time.

Risk score

51
cvss base
70.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
85.00
industry weight
1.21
freshness factor
0.50
exploitability factor
1.00
days old
49.00
vendor mismatch penalty
0.00

Path: operational

MITRE ATT&CK mapping

2 TTPs
Recon
Resource Dev
Initial Access
Persistence
Def. Evasion
Cred. Access
Discovery
Lateral Mov.
Collection
C2
Exfiltration
Impact
Conf.: high medium low

Procedure details

Technique Tactic Procedure Conf. Source
T1068
Exploitation for Privilege Escalation
Privilege Escalation Local attackers exploit an incorrect authorization vulnerability in Microsoft Windows WMI Providers (CVE-2026-50297) to escalate privileges from low-privileged code execution to higher privilege levels on the target system. high llm
T1047
Windows Management Instrumentation
Execution The vulnerability exists specifically within Microsoft Windows WMI Providers, which are abused due to incorrect authorization checks to achieve privilege escalation on affected Windows installations. high llm
ESC