Important CVSS 7.8 EPSS 0.00272 🔬 Patch diffed 2026-05 archive

Executive Summary

Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.

Overview

7.8
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Elevation of Privilege
Released May 12 2026
Last Updated May 12 2026
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.00272 — 0.19473 percentile
NVD CVSS 7.8 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Local
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 6.8

EPSS Score

0.00272
probability of exploitation in the next 30 days
0.19473 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

23 affected products
Product KB Article Severity Impact Restart Required
Windows 10 Version 1607 for 32-bit Systems 5087537 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1607 for x64-based Systems 5087537 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for 32-bit Systems 5087538 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for x64-based Systems 5087538 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for 32-bit Systems 5087544 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for ARM64-based Systems 5087544 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for x64-based Systems 5087544 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for 32-bit Systems 5094127 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for ARM64-based Systems 5094127 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for x64-based Systems 5094127 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for ARM64-based Systems 5087420 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for x64-based Systems 5093998 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 24H2 for ARM64-based Systems 5089549 (Security Update) 5089466 (Security Hotpatch Update) Important Elevation of Privilege 5082063 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.8457 10.0.26100.8390 Yes None Windows 11 Version 24H2 for x64-based Systems 5089549 (Security Update) 5089466 (Security Hotpatch Update) Important Elevation of Privilege 5082063 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.8457 10.0.26100.8390 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5089549 (Security Update) 5089466 (Security Hotpatch Update) Important Elevation of Privilege 5083769 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.8457 10.0.26200.8390 Yes None Windows 11 Version 25H2 for x64-based Systems 5089549 (Security Update) 5089466 (Security Hotpatch Update) Important Elevation of Privilege 5083769 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.8457 10.0.26200.8390 Yes None Windows 11 Version 26H1 for ARM64-based Systems 5089548 (Security Update) Important Elevation of Privilege Yes
Windows 11 version 26H1 for x64-based Systems 5089548 (Security Update) Important Elevation of Privilege Yes
Windows Server 2012 5087470 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 (Server Core installation) 5087470 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 R2 5087471 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 R2 (Server Core installation) 5087471 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2016 5087537 (Security Update) Important Elevation of Privilege Yes
Windows Server 2016 (Server Core installation) 5087537 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 5087538 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 (Server Core installation) 5087538 (Security Update) Important Elevation of Privilege Yes
Windows Server 2022 5087545 (Security Update) 5087424 (Security Hotpatch Update) Important Elevation of Privilege 5082142 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.5139 10.0.20348.5074 Yes None Windows Server 2022 (Server Core installation) 5087545 (Security Update) 5087424 (Security Hotpatch Update) Important Elevation of Privilege 5082142 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.5139 10.0.20348.5074 Yes None Windows Server 2022, 23H2 Edition (Server Core installation) 5087541 (Security Update) Important Elevation of Privilege Yes

Patches

10 patches
Article Type Restart
5087537 Security Update Yes
5087538 Security Update Yes
5087544 Security Update Yes
5094127 Security Update Yes
5087420 Security Update Yes
5093998 Security Update Yes
5089548 Security Update Yes
5087470 Monthly Rollup Yes
5087471 Monthly Rollup Yes
5087541 Security Update Yes

Patch Diff

ghidriff · wevtsvc.dll (KB5089549)

Improper access control (CWE-284) in the Windows Event Logging Service wevtsvc.dll channel configuration (max-size) handling, local EoP to SYSTEM. ChannelConfigReader::GetMaxSize returns the maximum size configured for an event-log channel. PRE: it derived the channel max size from a channel-policy property (ChannelPolicy::GetProperty(...,8)) that could be influenced without adequate access control, and did not distinguish protected channels - so a low-privileged user could affect the effective max-size of event-log channels, including protected ones such as Security. Diff of wevtsvc.dll 10.0.26100.8328 -> .8521 (spans the May 12 2026 fix build .8457, KB5089549; .8457 is not indexed on winbindex for this binary) confirms the fix: GetMaxSize is reworked to obtain the channel max size authoritatively from the registry (RegGetValueW for 'MaxSize' / 'MaxSizeUpper') and to special-case protected channels by name - for the 'Security' channel it returns enforced/clamped values (e.g. 0x2800000, 0x1400000, 0x101000) rather than honoring a user-influenceable policy property - restoring proper access control over protected event-log channel configuration. Note: GetMaxSize is the only functional change in this update (direct fix, not CFR-gated); it is presented at confirmed-changed level - the authoritative-registry + Security-channel clamp is the isolated change; the precise end-to-end EoP path from channel-size control is not fully derivable from the single getter.

Pre-patch version 10.0.26100.8328 Download
Post-patch version 10.0.26100.8521 Download
Function Address Change Note
ChannelConfigReader::GetMaxSize code change code (authoritative registry sourcing + protected-channel clamp) Pre: returned ChannelPolicy::GetProperty(this+0x40, 8) << 10 (user-influenceable policy property). Post: reads MaxSize/MaxSizeUpper via RegGetValueW from the channel's key, and for the 'Security' channel (wcscmp(name,L"Security")==0) returns enforced values (0x2800000 / 0x1400000 / 0x101000) instead of the policy property.
(direct fix) n/a note Not CFR-gated; GetMaxSize is the only functional change between .8328 and .8521 (the May .8457 build is not indexed for wevtsvc, so this pair spans the fix).
View full diff report View RCA report

Attack Path

Event-log channel max-size read from a user-influenceable policy property without protecting privileged channels

Attack path for CVE-2026-33834 Event-log channel max-size read from a user-influenceable policy property without protecting privileged channels 01 — ENTRY Local user interacts with Event Logging Service channel configuration wevtsvc.dll ChannelConfigReader::GetMaxSize resolves a channel's max size. AV:L/PR:L/AC:L. 02 — CONTROLLED INPUT Influences the channel-policy max-size property Pre-patch the max size came from ChannelPolicy::GetProperty(...,8) with inadequate access control and no protected-channel distinction. 03 — MISSING CHECK Protected channel configuration is not access-controlled (CWE-284) A low-privileged user can affect the effective max size of channels, including protected ones like Security. 04 — PATH Privileged event-log channel behavior is altered Manipulating protected channel configuration is leveraged toward privileged operations. 05 — PRIMITIVE Improper access control in the SYSTEM Event Log service -> EoP The May 2026 fix reads MaxSize authoritatively from the registry and clamps the Security channel's size.

Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.

Exploits & PoC

Detection Rules

Acknowledgments