CVE-2026-21508Patch(microsoft / windows_10_1607)

MEDIUMCVSS 7.0 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-426

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-31)
  • 8 total mentions across 7 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_server_2012windows_server_2016windows_server_2019

2 versions affected across 13 products

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-02-10: 1Mentions · 2026-02-12: 1Mentions · 2026-02-13: 1Mentions · 2026-02-14: 1Mentions · 2026-02-15: 1Mentions · 2026-03-10: 1Mentions · 2026-03-31: 2PoC Mentioned / Linked · 2026-02-14: 1Exploit Tool / Code · 2026-02-14: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-31: 2Technical Details · 2026-02-10: 1Technical Details · 2026-02-13: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-31: 202-1002-1202-1302-1402-1503-1003-31
Signal classification4 categories
Patch
337.5%
Disclosure
225.0%
General
225.0%
PoC
112.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-101
Disclosure1
2026-02-121
General1
2026-02-131
Disclosure1
2026-02-141
PoC1
2026-02-151
General1
2026-03-101
Patch1
2026-03-312
Patch2
Full discourse8 posts
  • Co11ateral@co11ateral
    Disclosure

    CVE-2026-21508 - Windows LPE via arbitrary COM object initialization The vulnerability essentially works by forcing a process running as system and that uses the undocumented function Windows_Storage!_SHCoCreateInstance, to create an arbitrary COM object of our choice. For this to happen the object must be associated with an already registered COM class that supports CLSCTX_INPROC_SERVER. Arbitrary COM object creation is archived by manipulating a CoCreateInstance call first argument #pentest #cve #redteam #dfir #blueteam

    Post summary

    The post outlines CVE‑2026‑21508 as a Windows local privilege escalation that permits arbitrary COM object creation via an undocumented function, but provides no PoC, exploit, or patch details.

    154126015214.9K
    1.5K followersView on X
  • 0patch@0patch
    Patch

    Micropatches released for Windows Storage Elevation of Privilege Vulnerability (CVE-2026-21508) https://blog.0patch.com/2026/03/micropatches-released-for-windows.html https://t.co/m7ak5uh7LG

    Post summary

    Micropatches have been released to fix the Windows Storage Elevation of Privilege vulnerability (CVE‑2026‑21508). No exploitation details or PoC are mentioned.

    14062849
    8.4K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-20841 2 - CVE-2026-23760 3 - CVE-2026-21508 4 - CVE-2024-27834 5 - CVE-2026-21514 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists the top trending CVEs without providing additional details or context.

    00020190
    1.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-12725 2 - CVE-2026-25253 3 - CVE-2026-1731 4 - CVE-2026-21508 5 - CVE-2025-9961 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A short post lists the top 5 trending CVE identifiers with related hashtags and a link, without providing additional context or actionable information.

    00010141
    1.7K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    『Microsoft's patch forces WUDFHost.exe to load sensitive registry keys from the machine registry hive instead of from the calling user's hive.』 0patch Blog: Micropatches released for Windows Storage Elevation of Privilege Vulnerability (CVE-2026-21508) https://blog.0patch.com/2026/03/micropatches-released-for-windows.html

    Post summary

    The text reports that Microsoft’s patch forces WUDFHost.exe to load sensitive registry keys from the machine registry hive, addressing the Windows Storage Elevation of Privilege Vulnerability (CVE-2026-21508).

    00000309
    6.7K followersView on X
  • Doctor Kloud@doctorkloud
    Patch

    Authentification défaillante dans Windows Storage : un attaquant local peut élever ses privilèges. Patch immédiat. Toute machine non corrigée expose ses ressources internes à une escalade silencieuse. #CVE-2026-21508 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21508

    Post summary

    The post highlights a Windows Storage authentication flaw (CVE‑2026‑21508) that permits local privilege escalation, urging users to apply the immediate patch referenced via Microsoft’s update guide.

    0000075
    13 followersView on X
  • samuel@BlckC0d3
    PoC

    Proof-of-concept for CVE-2026-21508 https://github.com/0xc4r/CVE-2026-21508_POC

    Post summary

    A proof‑of‑concept for CVE‑2026‑21508 has been posted on GitHub, showing how the vulnerability can be exploited, but no evidence of active attacks or patches is provided.

    0000035
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21508 Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-21508

    Post summary

    The text announces CVE‑2026‑21508, describing an improper authentication flaw in Windows Storage that allows local privilege escalation, but provides no details on exploitation, PoC, or patches.

    00000146
    56.5K followersView on X
CPE platform detail23 entries

23 of 23 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more