CVE-2026-33834 — Windows Event Logging Service Elevation of Privilege Vulnerability
Executive Summary
Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 Version 1607 for 32-bit Systems | 5087537 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5087537 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5087538 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5087538 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5087544 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5087544 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5087544 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5094127 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5094127 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5094127 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5087420 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5093998 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5089549 (Security Update) 5089466 (Security Hotpatch Update) Important Elevation of Privilege 5082063 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.8457 10.0.26100.8390 Yes None Windows 11 Version 24H2 for x64-based Systems 5089549 (Security Update) 5089466 (Security Hotpatch Update) Important Elevation of Privilege 5082063 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.8457 10.0.26100.8390 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5089549 (Security Update) 5089466 (Security Hotpatch Update) Important Elevation of Privilege 5083769 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.8457 10.0.26200.8390 Yes None Windows 11 Version 25H2 for x64-based Systems 5089549 (Security Update) 5089466 (Security Hotpatch Update) Important Elevation of Privilege 5083769 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.8457 10.0.26200.8390 Yes None Windows 11 Version 26H1 for ARM64-based Systems | 5089548 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 26H1 for x64-based Systems | 5089548 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 | 5087470 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 (Server Core installation) | 5087470 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 | 5087471 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5087471 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 | 5087537 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 (Server Core installation) | 5087537 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 | 5087538 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 (Server Core installation) | 5087538 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022 5087545 (Security Update) 5087424 (Security Hotpatch Update) Important Elevation of Privilege 5082142 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.5139 10.0.20348.5074 Yes None Windows Server 2022 (Server Core installation) 5087545 (Security Update) 5087424 (Security Hotpatch Update) Important Elevation of Privilege 5082142 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.5139 10.0.20348.5074 Yes None Windows Server 2022, 23H2 Edition (Server Core installation) | 5087541 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5087537 |
Security Update | Yes |
5087538 |
Security Update | Yes |
5087544 |
Security Update | Yes |
5094127 |
Security Update | Yes |
5087420 |
Security Update | Yes |
5093998 |
Security Update | Yes |
5089548 |
Security Update | Yes |
5087470 |
Monthly Rollup | Yes |
5087471 |
Monthly Rollup | Yes |
5087541 |
Security Update | Yes |
Patch Diff
Improper access control (CWE-284) in the Windows Event Logging Service wevtsvc.dll channel configuration (max-size) handling, local EoP to SYSTEM. ChannelConfigReader::GetMaxSize returns the maximum size configured for an event-log channel. PRE: it derived the channel max size from a channel-policy property (ChannelPolicy::GetProperty(...,8)) that could be influenced without adequate access control, and did not distinguish protected channels - so a low-privileged user could affect the effective max-size of event-log channels, including protected ones such as Security. Diff of wevtsvc.dll 10.0.26100.8328 -> .8521 (spans the May 12 2026 fix build .8457, KB5089549; .8457 is not indexed on winbindex for this binary) confirms the fix: GetMaxSize is reworked to obtain the channel max size authoritatively from the registry (RegGetValueW for 'MaxSize' / 'MaxSizeUpper') and to special-case protected channels by name - for the 'Security' channel it returns enforced/clamped values (e.g. 0x2800000, 0x1400000, 0x101000) rather than honoring a user-influenceable policy property - restoring proper access control over protected event-log channel configuration. Note: GetMaxSize is the only functional change in this update (direct fix, not CFR-gated); it is presented at confirmed-changed level - the authoritative-registry + Security-channel clamp is the isolated change; the precise end-to-end EoP path from channel-size control is not fully derivable from the single getter.
| Function | Address | Change | Note |
|---|---|---|---|
ChannelConfigReader::GetMaxSize |
code change |
code (authoritative registry sourcing + protected-channel clamp) | Pre: returned ChannelPolicy::GetProperty(this+0x40, 8) << 10 (user-influenceable policy property). Post: reads MaxSize/MaxSizeUpper via RegGetValueW from the channel's key, and for the 'Security' channel (wcscmp(name,L"Security")==0) returns enforced values (0x2800000 / 0x1400000 / 0x101000) instead of the policy property. |
(direct fix) |
n/a |
note | Not CFR-gated; GetMaxSize is the only functional change between .8328 and .8521 (the May .8457 build is not indexed for wevtsvc, so this pair spans the fix). |
Attack Path
Event-log channel max-size read from a user-influenceable policy property without protecting privileged channels
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.