Microsoft published security updates for a series of Windows elevation-of-privilege vulnerabilities affecting components including Core Messaging, CSC Service, Cryptographic Services, Win32k, and the COM+ Event System Service. The referenced flaws include CVE-2025-21378, CVE-2025-21184, CVE-2025-21414, CVE-2025-26634, CVE-2025-49727, CVE-2025-58725, and CVE-2025-62458, indicating a broad set of local privilege-escalation issues across core Windows subsystems.
Among them, Microsoft provided additional detail for CVE-2026-40377, an Important vulnerability in Microsoft Cryptographic Services caused by a heap-based buffer overflow. Microsoft said a locally authorized attacker with low privileges could exploit the flaw to gain SYSTEM privileges without user interaction; the issue received a CVSS 3.1 score of 7.8, was assessed as less likely to be exploited, and was not publicly disclosed or exploited at the time of publication. Microsoft said a fix was available and credited Bruce Dang of Calif.io for reporting the bug.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Microsoft disclosed CVE-2026-40377, an Important heap-based buffer overflow in Microsoft Cryptographic Services that could let a locally authorized low-privilege attacker gain SYSTEM privileges without user interaction. Microsoft said a fix was available, exploitation was considered less likely, and there was no evidence of public disclosure or in-the-wild exploitation at release.
Microsoft released security guidance for CVE-2025-62458, a Win32k elevation-of-privilege vulnerability. The publication indicates the issue was addressed in Microsoft's December 2025 security updates.
Microsoft published security update guidance for CVE-2025-58725, an elevation-of-privilege vulnerability in the Windows COM+ Event System Service. The listing indicates a fix was issued in the October 2025 Patch Tuesday release.
Microsoft released security guidance for CVE-2025-49727, a Win32k elevation-of-privilege vulnerability. The advisory's publication indicates the flaw was addressed in Microsoft's July 2025 security updates.
Microsoft disclosed CVE-2025-26634, another Windows Core Messaging elevation-of-privilege vulnerability, through its March 2025 Security Update Guide. The publication marks the availability of Microsoft's security update for the flaw.
Microsoft published security update guidance for CVE-2025-21184 and CVE-2025-21414, both elevation-of-privilege vulnerabilities affecting Windows Core Messaging. Their publication indicates fixes were made available in the February 2025 Patch Tuesday release.
Microsoft published security guidance for CVE-2025-21378, an elevation-of-privilege vulnerability in the Windows CSC Service. The advisory indicates the issue was addressed as part of Microsoft's January 2025 security updates.
10 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.