CyberRota Analysis
AI-GeneratedA vulnerability in the Windows RPC API allows an authorized attacker to exploit missing authentication for critical functions, enabling local privilege escalation. This could lead to unauthorized access and control over the affected system, posing significant risks to sensitive data and system integrity. Organizations using Windows should prioritize addressing this issue to mitigate potential exploitation by malicious insiders or compromised accounts.
CVE
CVE-2026-42976
Severity
HIGH
CVSS
7.8
EPSS
0.21%
Windows
Original NVD Description
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
Related CVEs
Other vulnerabilities affecting the same vendor(s)