CVE-2026-42980: Windows NT OS Kernel Local Privilege Escalation via WMI Integer Underflow (Public PoC)
CVE-2026-42980 (TL-2026-1707) is a high-severity software vulnerability scored CVSS 7.8, first published 2026-07-26. It has no confirmed attribution, affects Microsoft Windows 10, references 1 CVE (CVE-2026-42980), maps to 15 MITRE ATT&CK techniques (T1027.007, T1047, T1057), and is covered by 9 detection rules and 29 indicators of compromise.
Key facts for TL-2026-1707
- Threat ID
- TL-2026-1707
- Severity
- HIGH
- CVSS
- 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-26
- Last reviewed
- 2026-07-26
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, manufacturing, education, criticalinfrastructure, retail
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 29
Malware and tooling in CVE-2026-42980
Malware and tooling: CVE-2026-42980-POC
CVE-2026-42980 is a CVSS 7.8 integer-underflow vulnerability in the WMI serialization path of the Windows NT OS Kernel (ntoskrnl.exe) that lets a locally authenticated, low-privileged attacker corrupt kernel pool memory and escalate to NT AUTHORITY\SYSTEM. Microsoft patched it in the June 9, 2026 Patch Tuesday cycle; researcher G4sp4rCS published a fully weaponized PoC, build tooling, and a detailed technical writeup to GitHub on July 7, 2026, documenting a complete pool-grooming-to-token-theft exploitation chain and creating exploitation risk on any host that has not applied the June 2026 cumulative update.
How CVE-2026-42980 works
CVE-2026-42980 is a local privilege escalation vulnerability in the Windows NT OS Kernel caused by an unsigned 32-bit integer underflow (wraparound) in two related WMI (Windows Management Instrumentation) serialization routines inside ntoskrnl.exe: `nt!WmipQueryAllDataMultiple` (reached via IOCTL 0x22812C) and `nt!WmipQuerySingleMultiple` (reached via IOCTL 0x228130). Both functions maintain a 32-bit remaining-output-buffer counter and perform an unchecked unsigned subtraction, `OutputBufferLength -= AlignedSize`, of the provider-reported aligned record size. A capacity gate uses an estimated size formula, `(DataSize + 73) & ~7`, to admit an item, while the later subtraction uses the actual aligned size, `(ReturnedDataSize + 7) & ~7` — the mismatch between these two roundings lets an attacker craft a WNODE record whose aligned size exceeds the remaining counter, causing the subtraction to wrap to a very large unsigned value (e.g. a `0x94`-byte remaining capacity minus a `0x98`-byte record wraps to `0xFFFFFFFC`). The kernel then treats this wrapped value as legitimate remaining capacity and permits a second WNODE item to be serialized far out of bounds, corrupting adjacent non-paged pool allocations.
The public PoC (`CVE-2026-42980-POC`, author G4sp4rCS) documents a full, reliable exploitation chain reachable by any authenticated low-privileged local user via `\Device\WMIDataDevice`, requiring no user interaction: (1) build/OS-version detection to select correct offsets; (2) dynamic resolution of `NtFsControlFile`, `NtDeviceIoControlFile`, and the advapi32.dll WMI wrapper APIs `WmiOpenBlock`/`WmiQueryAllDataW`, paired with a runtime scan of a bundled WMI GUID dataset (candidate provider classes include `MSNdis_CoTransmitPduErrors`, `WmiMonitorConnectionParams`, and `MSPower_DeviceEnable`) to locate a WMI provider whose capacity-gate/actual-size mismatch is exploitable on the current build/VM/hardware profile; (3) non-paged pool grooming by spraying roughly 4,096 named pipes (pool tag `NpFr`) sized to match the WMI `SystemBuffer` allocation bucket (`METHOD_BUFFERED` IOCTL with padded input length `0xff0`), then freeing one pipe to create a targeted hole; (4) triggering the vulnerable WMI query so the kernel allocates `SystemBuffer` into the freed hole adjacent to a live `NP_DATA_QUEUE_ENTRY` (named-pipe queue entry) structure; (5) the underflow-driven out-of-bounds write corrupts the `DataSize` field of that queue entry; (6) calling `PeekNamedPipe` on the corrupted pipe over-reads adjacent kernel pool metadata at a stable offset (`0xfd0`), leaking kernel pointers and resolving the exploiting process's own base addresses; (7) a second underflow trigger reshapes the corrupted queue entry into an IRP-backed object, yielding an arbitrary kernel-memory read/write primitive; (8) using that primitive, the exploit walks the kernel's `ActiveProcessLinks` list from the current `EPROCESS` to PID 4 (the `System` process), reads its `Token` field, and overwrites the calling process's own `EPROCESS.Token` with it (Access Token Manipulation / Token Impersonation-Theft); (9) the exploit repairs the corrupted named-pipe structure to restore kernel stability and avoid a bugcheck/crash-triggered detection; (10) it then spawns `cmd.exe`, which inherits the just-stolen NT AUTHORITY\SYSTEM token, giving the attacker a fully privileged interactive shell.
Microsoft addressed the flaw in the June 9, 2026 Patch Tuesday cycle (Windows 11 24H2/25H2 via KB5094126, Windows 11 23H2 via KB5093998, and corresponding Windows 10 and Windows Server cumulative updates) by replacing the unchecked subtraction with saturating arithmetic gated behind an internal feature flag (`Feature_1045423416`): if the aligned size is less than the remaining length the subtraction proceeds normally, otherwise the remaining length saturates to zero instead of wrapping, which breaks the exploitation chain at the arithmetic layer by preventing the second WNODE from landing in the groomed adjacent object. At the time of patch release the vulnerability was not known to be exploited in the wild and carried no public exploit; NVD's CVSS 3.1 base score is 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), impact subscore 5.9, exploitability subscore 1.8, with weaknesses classified as CWE-191 (Integer Underflow) and CWE-122 (Heap-based Buffer Overflow); no CVSS v4.0 score had been published as of the last NVD update (2026-07-23). FIRST.org's EPSS model scores CVE-2026-42980 at 0.0695 (6.95% probability of exploitation in the next 30 days), placing it in the 93.43rd percentile of all scored CVEs — a comparatively high percentile for a vulnerability with no confirmed in-the-wild activity, driven by the public, fully weaponized PoC. The June 2026 Patch Tuesday cycle also addressed several other Windows elevation-of-privilege and remote-code-execution issues in adjacent components — a use-after-free RCE in the Windows Kernel (CVE-2026-45657), and use-after-free EoP flaws in DWM Core Library (CVE-2026-42905), the Microsoft Graphics component (CVE-2026-42986), and Winlogon (CVE-2026-42989) — released the same day but tracked as separate, technically unrelated vulnerabilities.
On July 7, 2026, security researcher G4sp4rCS published the fully working proof-of-concept to the public GitHub repository `G4sp4rCS/CVE-2026-42980-POC`, including C source (`src/cve_2026_42980_lpe.c`, `src/helpers.c`, `src/wmi_guids.h`), a `Makefile` and PowerShell build script (`build.ps1`), a proof screenshot (`assets/photo-poc-system.jpg`), and English/Spanish technical writeups (`writeup-en.md`, `writeup-es.md`), explicitly framed for educational, defensive-research, and authorized-testing use only, to be run exclusively in isolated lab systems. Cyber Security News covered the public release on July 22, 2026, and vulnerability-intelligence platforms (cvereports.com, cvemon/intruder.io) published independent technical breakdowns of the exploitation chain around the same date. As of this writing CVE-2026-42980 has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, and there is no confirmed evidence of active in-the-wild exploitation — its elevated 93.43rd-percentile EPSS score reflects the public PoC's reliability and reach, not observed campaign activity.
The vulnerability affects a broad range of currently supported Windows client and server releases (Windows 10 1607/1809/21H2/22H2, Windows 11 23H2/24H2/25H2/26H1 across x86/x64/ARM64, and Windows Server 2012/2012 R2/2016/2019/2022/2025), making it broadly relevant to enterprise and consumer estates that have not applied the June 2026 or later cumulative security update.
MITRE ATT&CK techniques used in TL-2026-1707
Defense Evasion
T1027.007 Dynamic API Resolution; T1134 Access Token Manipulation; T1211 Exploitation for Stealth
Execution
T1047 Windows Management Instrumentation; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1106 Native API
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1120 Peripheral Device Discovery; T1518 Software Discovery
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1134.001 Token Impersonation/Theft
Initial Access
Resource Development
Affected products and versions in CVE-2026-42980
- Microsoft — Windows 10
Vulnerable versions: 1607; 1809; 21H2; 22H2
Fixed in: June 9, 2026 or later cumulative security update - Microsoft — Windows 11
Vulnerable versions: 23H2; 24H2; 25H2; 26H1
Fixed in: KB5094126 (24H2/25H2); KB5093998 (23H2); or later cumulative update - Microsoft — Windows Server
Vulnerable versions: 2012; 2012 R2; 2016; 2019; 2022; 2025
Fixed in: June 9, 2026 or later cumulative security update
Remediation for CVE-2026-42980
Patches
- Microsoft June 9, 2026 Patch Tuesday cumulative updates — KB5094126 (Windows 11 24H2/25H2), KB5093998 (Windows 11 23H2), and equivalent Windows 10 / Windows Server June 2026 updates — apply saturating (branchless) subtraction to the vulnerable WmipQueryAllDataMultiple/WmipQuerySingleMultiple WMI serialization paths in ntoskrnl.exe.
Immediate actions
- Install the June 9, 2026 (or later) Microsoft cumulative security updates that fix CVE-2026-42980 — KB5094126 for Windows 11 24H2/25H2, KB5093998 for Windows 11 23H2, and the corresponding Windows 10 and Windows Server June 2026 cumulative updates — which apply saturating-arithmetic logic (gated behind internal flag Feature_1045423416) to the WmipQueryAllDataMultiple/WmipQuerySingleMultiple code paths in ntoskrnl.exe.
- On systems that cannot be patched immediately, harden the ACLs on \Device\WMIDataDevice to block access from standard, low-privileged local accounts.
- Audit and minimize the number of interactive/low-privileged local accounts on high-value Windows hosts to shrink the population that can reach this local-only attack vector.
- Prioritize patch deployment on multi-user, terminal-server, and shared-workstation environments where large numbers of low-privileged local sessions exist.
Workarounds
- Harden \Device\WMIDataDevice ACLs to deny access from standard/low-privileged users pending patch deployment.
- Where operationally acceptable, disable or restrict the WMI (Winmgmt) service on hosts that do not require it until patched.
- Rate-limit or alert on abnormal named-pipe creation volume per session as a compensating control against the pool-grooming stage of the documented exploit.
Longer-term hardening
- Add EDR/SIEM detections for anomalous NT AUTHORITY\SYSTEM child processes (e.g. cmd.exe) spawned from low-privileged parent processes, and for rapid/high-volume named-pipe creation (~4096 pipes, pool tag NpFr) immediately followed by access to \Device\WMIDataDevice.
- Feed kernel-mode crash and bug-check telemetry (unexpected ntoskrnl.exe faults tied to WMI query handling, especially IOCTLs 0x22812C/0x228130) into SOC monitoring pipelines.
- Track the public G4sp4rCS/CVE-2026-42980-POC repository and any derivative forks for tooling changes that could indicate weaponization, automation, or wormable packaging.
- Verify patch presence via endpoint configuration/feature-flag telemetry (Feature_1045423416) rather than relying solely on KB installation status, given cumulative-update supersedence.
- Enforce application allow-listing on endpoints to reduce the ability of an attacker to stage and execute an unsigned local exploit binary.
CVEs associated with CVE-2026-42980
Weaknesses (CWE) in CVE-2026-42980
CWE-191, CWE-122
Timeline of CVE-2026-42980
- The same June 2026 Patch Tuesday cycle also fixes several other Windows kernel-adjacent vulnerabilities as separate, technically unrelated issues: a use-after-free RCE in the Windows Kernel (CVE-2026-45657), and use-after-free elevation-of-privilege flaws in DWM Core Library (CVE-2026-42905), the Graphics component (CVE-2026-42986), and Winlogon (CVE-2026-42989), per Qualys's Patch Tuesday review.
- Microsoft ships cumulative security updates KB5094126 (Windows 11 24H2/25H2) and KB5093998 (Windows 11 23H2), plus corresponding Windows 10 and Windows Server updates, replacing the unchecked subtraction in WmipQueryAllDataMultiple/WmipQuerySingleMultiple with saturating arithmetic gated behind internal flag Feature_1045423416.
- CVE-2026-42980 is published/patched by Microsoft as part of the June 2026 Patch Tuesday release; the NVD record is created the same day with CVSS 3.1 base score 7.8 (impact 5.9, exploitability 1.8), classified under CWE-191 and CWE-122.
- Researcher G4sp4rCS publishes a fully working proof-of-concept exploit and English/Spanish technical writeups for CVE-2026-42980 to the public GitHub repository CVE-2026-42980-POC, including C source, helper/GUID headers, a Makefile, a PowerShell build script, and a proof-of-exploitation screenshot.
- Cyber Security News publishes an article covering the public release of the CVE-2026-42980 PoC, flagging exploitation risk for unpatched Windows hosts and recommending expedited patching plus local-logon restriction.
- Vulnerability-intelligence outlet cvereports.com publishes an independent technical breakdown of the full exploitation chain — pool grooming via named pipes, PeekNamedPipe-based kernel pointer leak, ActiveProcessLinks token theft — corroborating the details in the public PoC writeup.
- The NVD record for CVE-2026-42980 is last-modified, reflecting updated scoring/weakness data following the public PoC disclosure; no CVSS v4.0 score has been published as of this update.
- TL-Intel Harness HUNT phase selects CVE-2026-42980 for tracking based on public PoC availability and the local low-privilege-to-SYSTEM exploitation risk it poses to unpatched hosts.
Sources cited for CVE-2026-42980
- PoC Exploit Released for Windows NT OS Kernel Privilege Escalation Vulnerability
- CVE-2026-42980 Detail - NVD
- CVE-2026-42980 - Security Update Guide - Microsoft - NT OS Kernel Elevation of Privilege Vulnerability
- G4sp4rCS/CVE-2026-42980-POC
- G4sp4rCS/CVE-2026-42980-POC — writeup-en.md (technical writeup)
- CVE-2026-42980: Windows Kernel Local Privilege Escalation via WMI Integer Underflow
- Microsoft and Adobe Patch Tuesday, June 2026 Security Update Review
- CVE-2026-42980 - Overview, Insights & Trends
- June 9, 2026-KB5094126 (OS Builds 26200.8655 and 26100.8655)
- FIRST.org EPSS API — CVE-2026-42980
Threats related to CVE-2026-42980
- CVE-2026-46215: Linux Kernel DRM GEM_CHANGE_HANDLE Use-After-Free Local Root Privilege Escalation
- Windows Kernel CVE-2026-40369 — NtQuerySystemInformation ProbeForWrite Bypass Enables Arbitrary Kernel Memory Increment → SYSTEM LPE from Browser Sandboxes (Ori Nimron)
- SCTPhantom (CVE-2026-64564): 18-Year-Old Use-After-Free in Linux Kernel SCTP ASCONF Handling Enables Local Privilege Escalation
Detection coverage for TL-2026-1707
As of 2026-07-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1707 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.