Microsoft Windows WMI Providers Vulnerability Allows Local Privilege Escalation
A local privilege escalation vulnerability (ZDI-26-446, CVE-2026-50297) in Microsoft Windows WMI Providers allows attackers with low-privileged code execution to gain higher privileges.

A newly disclosed vulnerability in Microsoft Windows, tracked as ZDI-26-446 and assigned CVE-2026-50297, presents a significant risk of local privilege escalation. The flaw resides within the configuration of Windows Management Instrumentation (WMI) providers, a core component for system management and monitoring.
Exploitation of this vulnerability requires an attacker to first gain the ability to execute low-privileged code on the target system. Once this initial foothold is established, the attacker can leverage the incorrect authorization checks within WMI providers to elevate their privileges. This could allow them to perform actions typically reserved for administrators or even execute arbitrary code in the context of a higher-privileged user.
The Zero Day Initiative (ZDI), which disclosed the vulnerability, assigned it a CVSS score of 7.0, indicating a high severity. This score reflects the potential for significant impact on affected systems, particularly in environments where an attacker might already have a limited presence.
Microsoft has acknowledged the vulnerability and released an update to address the issue. Users are strongly advised to apply the security patch promptly to mitigate the risk of exploitation. Further details on the update can be found on Microsoft's Security Update Guide.
The disclosure timeline indicates that the vulnerability was reported to Microsoft on July 21, 2026, with a coordinated public release of the advisory on the same day. The advisory was updated shortly thereafter, suggesting a rapid response from both ZDI and Microsoft.
The vulnerability was discovered and reported by security researcher mad31k. This finding underscores the ongoing challenges in securing complex operating system components like WMI, which are essential for system functionality but can also present attack vectors if not properly secured.
While the vulnerability requires local code execution, it can be chained with other exploits or social engineering tactics to achieve a full system compromise. Organizations should ensure their endpoint detection and response (EDR) solutions are configured to detect suspicious WMI activity and privilege escalation attempts.
This new advisory from Zero Day Initiative details a specific local privilege escalation vulnerability within Microsoft Windows WMI Providers, identified as ZDI-26-445 and assigned CVE-2026-50325. The vulnerability stems from incorrect authorization in WMI provider configurations, allowing attackers with low-privileged code execution to gain higher privileges. Microsoft has released an update to address this specific flaw, with the CVSS score rated at 7.0.