CVE-2026-42902: Microsoft PowerToys Elevation of Privilege Vulnerability
Published Jun 9, 2026
·Updated
Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.
Affected Software
1 affected componentFixes available
Microsoft PowerToys
Event History
Jun 9, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:04 PM
Data Sourced
via MITRE·05:04 PM
DescriptionSeverity
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness