CVE-2026-21253Disclosure(microsoft / windows_10_1607)

LOWCVSS 7.0 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-02-10); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_server_2012windows_server_2016windows_server_2019

2 versions affected across 13 products

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-10: 1Mentions · 2026-02-11: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-09: 1PoC Mentioned / Linked · 2026-02-27: 1PoC Mentioned / Linked · 2026-03-09: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-03-09: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-09: 102-1002-1102-2702-2803-09
Signal classification4 categories
Disclosure
240.0%
PoC
120.0%
General
120.0%
Patch
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-101
Disclosure1
2026-02-111
Disclosure1
2026-02-271
PoC1
2026-02-281
General1
2026-03-091
Patch1
Full discourse5 posts
  • PatchPoint.Official@_patchpoint_
    PoC

    We released a demo video for the CVE-2026-21253 Windows Mailslot File System Elevation of Privilege Vulnerability, patched by Microsoft in Feb 2026. https://youtu.be/ZFLOGno6Hc4 Watch the video and subscribe to our private vulnerability PoC and detailed report service at http://Patchpoint.io. #Windows #Microsoft #MailslotFS #Vulnerability #CVE_2026_21253

    Post summary

    The post announces a demo video and PoC for CVE‑2026‑21253, a Windows Mailslot File System privilege‑escalation flaw, while noting Microsoft’s patch issued in February 2026.

    012024152.6K
    461 followersView on X
  • kawn@kawn2020
    Disclosure

    #windowsupdate #microsoft (つづき) ・CVE-2026-21238 7.8 Windows Ancillary Function Driver for WinSock ・CVE-2026-21241 7  Windows Ancillary Function Driver for WinSock ・CVE-2026-21253 7  メールスロット ファイル システム ・CVE-2026-21511 7.5 Microsoft Office Outlook

    Post summary

    A brief update lists several recent Microsoft CVEs with their CVSS scores and affected components, serving as a disclosure of upcoming vulnerabilities but lacking details on exploitation or mitigations.

    10000123
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21253 Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-21253

    Post summary

    The post announces CVE‑2026‑21253, describing a use‑after‑free bug in the Mailslot File System that could allow a local, authorized attacker to elevate privileges. No evidence of PoC, exploitation, patch, or false positive is provided.

    00010129
    56.5K followersView on X
  • Vicarius@vicariusltd
    Patch

    Not what you want to hear 🥲 ____ CVE of the Week CVE-2026-21253: Elevation of Privilege in Windows Mailslot File System This use-after-free flaw allows an authorized local attacker with low privileges to escalate their permissions to SYSTEM level, bypassing critical OS security boundaries. Exploiting this vulnerability could result in: - Full System Takeover: Attackers can gain the highest level of administrative control. - With SYSTEM privileges, attackers can disable security tools, access sensitive local files, and establish permanent backdoors. Recommended actions: 1. Apply February 2026 Updates: Install the latest cumulative security updates to patch the rasman.dll component. 2. Temporary mitigation: Disable the Mailslot File System driver by setting the registry value HKLM\SYSTEM\CurrentControlSet\Services\Msfs\Start to 4. (Note: This may impact legacy applications that rely on Mailslot IPC). If you cannot immediately update, proceed to mitigation. Follow the instructions outlined in these scripts to reduce exposure: Detection: https://www.vicarius.io/vsociety/posts/cve-2026-21253-detection-script-elevation-of-privilege-vulnerability-in-mailslot-file-system Remediation: https://www.vicarius.io/vsociety/posts/cve-2026-21253-mitigation-script-elevation-of-privilege-vulnerability-in-mailslot-file-system Let us know if you need help securing your systems or understanding these steps further 🤝

    Post summary

    The post announces CVE-2026-21253, a use‑after‑free privilege‑escalation flaw, and offers patch and mitigation guidance with detection and remediation scripts, but reports no active exploitation or exploit code.

    00000135
    2.2K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-35202 2 - CVE-2019-12735 3 - CVE-2025-40552 4 - CVE-2026-21253 5 - CVE-2026-28515 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply enumerates five CVE identifiers as trending topics, providing no additional information on exploitation, patches, or technical specifics.

    00000342
    1.7K followersView on X
CPE platform detail23 entries

23 of 23 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016--x64
OSmicrosoftwindows_server_2019--x64
OSmicrosoftwindows_server_2022--x64
OSmicrosoftwindows_server_2022_23h2--x64
OSmicrosoftwindows_server_2025--x64

Explore more