
Windows WalletService Flaw Lets Local Attackers Gain SYSTEM Privileges
A newly disclosed local privilege-escalation vulnerability in Windows WalletService, tracked as CVE-2026-49176, allows a standard user to escalate to NT AUTHORITY\SYSTEM by abusing the way the service resolves file paths and processes database callbacks. Microsoft rates the flaw Important, with a CVSS 3.1 score of 7.8, mapping it to CWE-269 (Improper Privilege Management) and CWE-59 […]
The post Windows WalletService Flaw Lets Local Attackers Gain SYSTEM Privileges appeared first on Cyber Security News.