A public proof-of-concept exploit has been released for CVE-2026-42980, a high-severity Windows NT OS Kernel elevation-of-privilege flaw that allows a locally authenticated low-privileged user to gain NT AUTHORITY\SYSTEM access. The vulnerability stems from an integer underflow in the kernel's WMI serialization code that can trigger a heap-based buffer overflow and kernel memory corruption on supported Windows client and server releases, including Windows 10 Version 1607 and later builds.
Microsoft patched the issue in its June 2026 Patch Tuesday updates, assigned it a CVSS 3.1 score of 7.8, and assessed exploitation as "more likely." While there is no confirmed in-the-wild exploitation reported so far, the availability of exploit code raises the risk that attackers could use the bug after initial compromise to obtain full machine control, particularly on shared systems and servers. Microsoft has not provided a configuration workaround, making prompt deployment and validation of the June 2026 cumulative updates the primary mitigation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A public proof-of-concept exploit for CVE-2026-42980 became available, increasing the risk that local authenticated attackers could escalate privileges to SYSTEM on affected Windows systems. The references note that no vendor had confirmed in-the-wild exploitation at the time of reporting.
Microsoft fixed CVE-2026-42980, a Windows NT OS Kernel elevation-of-privilege flaw caused by an integer underflow in WMI serialization code, in its June 9, 2026 Patch Tuesday updates. The company rated exploitation as "more likely" and provided no configuration workaround beyond applying the cumulative updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.