Sceawere

Vulnerability Detail

CVE-2026-62721UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

User-Mode Power Service Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
7h ago
Vendor
Microsoft
Product
Windows 10 Version 1607
Attack Type
CWE-1220: Insufficient Granularity of Access Control
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-08-11T17:18:22.870Z",
  "pubdate": "2026-08-11T17:18:22.870Z",
  "executiveSummary": "An insufficient granularity of access control vulnerability exists within the User-Mode Power Service (UMPS), leading to local privilege escalation risks.\nThe flaw allows an authorized malicious actor with local system access to manipulate service interactions and elevate their execution privileges.\nThe affected product is the User-Mode Power Service, impacting systems utilizing this component for power management operations.\nThe primary risk implication is the unauthorized compromise of host integrity and confidentiality, as an attacker can transition from a standard user context to higher-privileged execution states.\nAttacker capabilities are constrained by the requirement for prior local access; however, the vulnerability enables an otherwise restricted user to bypass standard authorization boundaries enforced by the operating system.\nExploitation requirements dictate that the attacker must already be authorized on the local host to interact with the vulnerable User-Mode Power Service interfaces, leveraging the overly permissive access controls to execute unauthorized administrative actions.",
  "technicalDetails": "The root cause of the vulnerability stems from insufficient granularity of access control within the User-Mode Power Service (UMPS). Specifically, the service exposes internal methods, communication channels, or object handles that fail to properly enforce principle-of-least-privilege checks during client interaction.\nThe vulnerable component is the User-Mode Power Service, which processes power-related management requests and interacts with core operating system primitives.\nAuthentication requirements dictate that the user must possess valid local credentials and authorization to interface with the service, though potentially restricted to a low-privilege security context.\nPrivilege requirements are minimal with respect to the exploit phase, requiring only standard local user privileges to initiate communication with the vulnerable service.\nNetwork exposure is strictly local, as the attack vector does not rely on remote network interfaces but rather on local inter-process communication (IPC), Named Pipes, Local Procedure Calls (LPC), or COM/RPC interfaces exposed by the service.\nThe attack flow proceeds as follows: First, the local attacker establishes a communication channel with the User-Mode Power Service. Second, due to the lack of granular access control checks on specific service functions or underlying resource handlers, the attacker submits crafted commands or data structures that are improperly validated. Third, the service executes the requested operations under its own elevated security context rather than restricting the action based on the caller's lower privilege level. Finally, this improper handling permits the execution of privileged routines, arbitrary file manipulation, or the spawning of processes inheriting the heightened permissions of the service.\nPayload behavior involves leveraging the unintended administrative capabilities granted through the flawed service interface to interact with protected system resources, inject code into privileged processes, or create persistence mechanisms.\nThe post-exploitation impact includes complete local compromise, allowing the attacker to read sensitive data, modify system configurations, install persistent malware, or pivot to further administrative privileges across the host environment."
}
CVE-2026-62721: User-Mode Power Service Privilege Escalation (HIGH Severity, CVSS: 7.8) - Sceawere