Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Adobe Acrobat Flaw Steals WhatsApp Chats From 329M Users
July 22, 2026
Critical RefluxFS Linux Kernel Bug Lets Attackers Gain Root Access
July 22, 2026
Critical Microsoft 365 Flaw Lets Attackers Bypass MFA, Hijack Sessions
July 22, 2026
Home/CyberSecurity News/Critical Windows NT OS Kernel Bug Lets Attackers Escalate Privileges
CyberSecurity News

Critical Windows NT OS Kernel Bug Lets Attackers Escalate Privileges

Key Takeaways A critical local privilege escalation vulnerability, CVE-2026-42980, has been disclosed in the Windows NT OS Kernel. This flaw stems from an integer underflow, allowing low-privileged...

Marcus Rodriguez
Marcus Rodriguez
July 22, 2026 3 Min Read
3 0

Key Takeaways

  • A critical local privilege escalation vulnerability, CVE-2026-42980, has been disclosed in the Windows NT OS Kernel.
  • This flaw stems from an integer underflow, allowing low-privileged local attackers to gain NT AUTHORITYSYSTEM access.
  • A public proof-of-concept (PoC) exploit has been released by security researcher G4sp4rCS.
  • Microsoft has issued a patch for this high-severity vulnerability; immediate application is strongly advised.

A significant security flaw, tracked as CVE-2026-42980, has been identified within the Windows NT OS Kernel, posing a serious risk of local privilege escalation. This vulnerability, now accompanied by public exploit code, allows attackers to elevate their access to the highest possible system privileges.

Table Of Content

  • Key Takeaways
  • PoC for Windows NT OS Kernel Vulnerability
  • What You Should Do

The core of the issue lies in an integer underflow condition within a specific kernel-mode code path. This arithmetic error can be triggered by a locally authenticated user with minimal privileges, leading to unpredictable kernel behavior and ultimately enabling the execution of arbitrary code with elevated permissions.

Successful exploitation of CVE-2026-42980 grants an attacker complete control over the compromised Windows system, effectively elevating their session from a standard user account to NT AUTHORITYSYSTEM.

PoC for Windows NT OS Kernel Vulnerability

Security researcher G4sp4rCS recently published a working PoC exploit for CVE-2026-42980 on GitHub. The repository includes all necessary components: build scripts, the full source code, and a detailed technical write-up in English.

The provided source code is written in C and targets a vulnerable Windows Management Instrumentation (WMI)-related kernel path. It is accompanied by helper files and build tools, specifically a Makefile and a PowerShell script, designed to compile the exploit binary on Windows systems using MSVC toolchains.

According to the researcher’s disclosure, the exploit is strictly intended for educational purposes, defensive research, and authorized testing within controlled lab environments. It is explicitly cautioned that the code should only be executed in isolated settings to prevent unintended consequences.

This vulnerability is classified as high severity due to its low attack complexity: it requires only local access with minimal privileges and no user interaction to achieve full system compromise. The public release of the PoC significantly lowers the bar for threat actors to integrate this technique into their post-compromise activities, such as lateral movement and privilege escalation on both Windows workstations and servers.

Common attack scenarios involve deploying this PoC, or a modified version, after initial infiltration through methods like phishing, browser exploits, or other malware. This allows adversaries to break out of restricted user contexts and disable security controls at the kernel level.

Microsoft has already released a kernel update that addresses CVE-2026-42980 as part of its standard security update cycle. System administrators are strongly urged to apply these patches to all affected Windows systems without delay.

What You Should Do

  • Immediately apply the latest security updates from Microsoft to patch CVE-2026-42980 across all Windows NT OS Kernel environments.
  • Verify patch deployment using endpoint management platforms, prioritizing critical multi-user and terminal server environments.
  • Restrict local logon rights to only trusted accounts to minimize the pool of potential attackers who could exploit this flaw.
  • Implement application allow-listing policies to prevent the execution of untrusted binaries on endpoints.
  • Monitor systems diligently for any suspicious privilege escalation attempts or unusual kernel-level activity.
  • If testing the PoC, ensure it is conducted exclusively within tightly controlled and isolated lab environments.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitMalwarePatchphishingSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical AWS Kiro RCE Vulnerability Found in Website Text

Next Post

Critical Microsoft 365 Flaw Lets Attackers Bypass MFA, Hijack Sessions

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
ASUS Patches Critical Router Vulnerability CVE-2024-XXXX for Remote Command Execution
July 22, 2026
Iranian Hackers Exploit Fortinet and Microsoft Flaws for Persistent Access
July 22, 2026
Royal Ransomware Leverages Qbot, Cobalt Strike to Rapidly Compromise Windows Domains
July 22, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us