Skip to main content
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisoryinitial-access-method

Microsoft discloses multiple Windows elevation-of-privilege flaws across kernel and core components

Updated 3d agoFirst seen May 25, 202616 sources

Microsoft published security advisories for a series of Windows elevation-of-privilege vulnerabilities affecting the Windows Kernel, File Explorer, Windows Management Service, Windows UI XAML Phone DatePickerFlyout, Windows Graphics Component, Windows Storage, and the DirectX Graphics Kernel. The referenced flaws include CVE-2026-26132, CVE-2025-62565, CVE-2025-54103, CVE-2025-54111, CVE-2025-55693, CVE-2024-38249, CVE-2025-62573, CVE-2024-38248, and CVE-2025-55678.

The disclosures indicate a broad patching effort spanning core operating system subsystems and user-facing Windows components, with repeated exposure in privileged areas such as the kernel and graphics stack. For defenders, the concentration of elevation-of-privilege issues across these components raises the risk that attackers could chain local access or code execution with privilege escalation to gain SYSTEM-level or otherwise expanded rights on affected Windows systems, making prompt validation and deployment of Microsoft updates a priority.

Share:
Microsoft discloses multiple Windows elevation-of-privilege flaws across kernel and core components
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

16 events from the most recent confirmed update back to the earliest known activity.

16 EVENTS
Apr 14, 20261mo ago

Microsoft publishes CVE-2026-26165 Windows Shell EoP advisory

Microsoft published CVE-2026-26165 in its Security Update Guide as a Windows Shell Elevation of Privilege vulnerability. The listing marks Microsoft's public disclosure of the flaw and associated security update information.

CVE-2026-26165 - Security Update Guide - Microsoft - Windows Shell Elevation of Privilege Vulnerability

Microsoft publishes CVE-2026-27916 UPnP Device Host EoP advisory

Microsoft disclosed CVE-2026-27916 in the Security Update Guide as a Windows Universal Plug and Play (UPnP) Device Host elevation of privilege vulnerability caused by a use-after-free issue. The advisory indicates an official fix is available and that no public exploitation or prior public disclosure was reported at publication.

CVE-2026-27916 - Security Update Guide - Microsoft - Windows UPnP Device Host Elevation of Privilege Vulnerability
Mar 10, 20263mo ago

Microsoft publishes CVE-2026-26132 Windows Kernel EoP advisory

Microsoft published CVE-2026-26132 as a Windows Kernel Elevation of Privilege vulnerability in its Security Update Guide. This is the public advisory date visible in the provided reference.

Dec 9, 20256mo ago

Microsoft publishes CVE-2025-62573 DirectX Graphics Kernel EoP advisory

Microsoft disclosed CVE-2025-62573 as a DirectX Graphics Kernel Elevation of Privilege vulnerability in the Security Update Guide. The publication marks Microsoft's public documentation of the flaw.

Microsoft publishes CVE-2025-62565 File Explorer EoP advisory

Microsoft published CVE-2025-62565 in the Security Update Guide as a Windows File Explorer Elevation of Privilege vulnerability. The entry indicates formal disclosure of the issue by Microsoft.

Oct 14, 20258mo ago

Microsoft publishes CVE-2025-58728 Windows Bluetooth Service EoP advisory

Microsoft published CVE-2025-58728 in the Security Update Guide as a Windows Bluetooth Service Elevation of Privilege vulnerability. The listing marks Microsoft's public disclosure of the flaw and associated security update information.

CVE-2025-58728 - Security Update Guide - Microsoft - Windows Bluetooth Service Elevation of Privilege Vulnerability

Microsoft publishes CVE-2025-55693 Windows Kernel EoP advisory

Microsoft added CVE-2025-55693 to the Security Update Guide as a Windows Kernel Elevation of Privilege vulnerability. This represents Microsoft's public advisory for the flaw.

Microsoft publishes CVE-2025-55678 DirectX Graphics Kernel EoP advisory

Microsoft published CVE-2025-55678 as a DirectX Graphics Kernel Elevation of Privilege vulnerability. The Security Update Guide entry marks the vulnerability's public release by Microsoft.

Sep 18, 20258mo ago

Microsoft publishes CVE-2025-59215 Windows Graphics Component EoP advisory

Microsoft published CVE-2025-59215 in its Security Update Guide as a Windows Graphics Component Elevation of Privilege vulnerability. The listing marks Microsoft's public disclosure of the flaw and associated security update information.

CVE-2025-59215 - Security Update Guide - Microsoft - Windows Graphics Component Elevation of Privilege Vulnerability
Sep 9, 20259mo ago

Microsoft publishes CVE-2025-54111 UI XAML Phone DatePickerFlyout EoP advisory

Microsoft disclosed CVE-2025-54111 in the Security Update Guide as a Windows UI XAML Phone DatePickerFlyout Elevation of Privilege vulnerability. The listing indicates the issue was formally documented by Microsoft.

Microsoft publishes CVE-2025-54103 Windows Management Service EoP advisory

Microsoft published CVE-2025-54103 as a Windows Management Service Elevation of Privilege vulnerability in the Security Update Guide. The entry reflects public disclosure and associated security update availability.

Jul 8, 202511mo ago

Microsoft publishes CVE-2025-49726 Windows Notification EoP advisory

Microsoft published CVE-2025-49726 in its Security Update Guide as a Windows Notification Elevation of Privilege vulnerability. The listing marks Microsoft's public disclosure of the flaw and associated security update information.

CVE-2025-49726 - Security Update Guide - Microsoft - Windows Notification Elevation of Privilege Vulnerability
Mar 11, 20251y ago

Microsoft publishes CVE-2025-24983 Win32 Kernel Subsystem EoP advisory

Microsoft disclosed CVE-2025-24983 as a Windows Win32 Kernel Subsystem elevation-of-privilege vulnerability caused by a use-after-free flaw. The advisory states the bug was exploited in the wild, functional exploit code is available, and an official fix was released.

CVE-2025-24983 - Security Update Guide - Microsoft - Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Dec 10, 20241y ago

Microsoft publishes CVE-2024-49074 Windows Kernel-Mode Driver EoP advisory

Microsoft published CVE-2024-49074 in its Security Update Guide as a Windows Kernel-Mode Driver Elevation of Privilege vulnerability. The listing marks Microsoft's public disclosure of the flaw and associated security update information.

CVE-2024-49074 - Security Update Guide - Microsoft - Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Sep 10, 20242y ago

Microsoft publishes CVE-2024-38249 Windows Graphics Component EoP advisory

Microsoft published CVE-2024-38249 in its Security Update Guide as a Windows Graphics Component Elevation of Privilege vulnerability. This marks public disclosure of the vulnerability through Microsoft's advisory channel.

Microsoft publishes CVE-2024-38248 Windows Storage EoP advisory

Microsoft added CVE-2024-38248 to its Security Update Guide as a Windows Storage Elevation of Privilege vulnerability. The publication indicates a security update or advisory was released for the issue.

SOURCE COVERAGE

Sources

16 references tracked. Mallory keeps watching after this page renders.

16 SOURCESView all
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.