
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21245 is a heap-based buffer overflow vulnerability in the Windows Kernel that allows an authorized local attacker to elevate privileges. It was disclosed and patched on February 10, 2026, as part of Microsoft's February 2026 Patch Tuesday security update. Affected products include Windows 11 24H2 (before build 10.0.26100.7781), Windows 11 25H2 (before build 10.0.26200.7781), and Windows Server 2025 (before build 10.0.26100.32313). The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The root cause is a heap-based buffer overflow (CWE-122) in the Windows Kernel, which also involves out-of-bounds write behavior (CWE-787). An attacker with low-privileged local access can trigger the overflow to corrupt kernel heap memory, enabling privilege escalation without requiring user interaction. The attack vector is local, requires low privileges, and has low attack complexity, meaning exploitation is straightforward once local access is obtained. No public proof-of-concept or detailed technical write-up has been identified at this time (Microsoft MSRC, Qualys Blog).
Successful exploitation grants the attacker SYSTEM-level privileges, resulting in complete compromise of the affected system across confidentiality, integrity, and availability dimensions. An attacker who already has a foothold on the system (e.g., via phishing or initial access malware) could leverage this vulnerability to escape restricted user contexts, disable security controls, persist on the system, or facilitate lateral movement within a network. Affected systems include Windows 11 24H2, Windows 11 25H2, and Windows Server 2025 (Microsoft MSRC, Qualys Blog).
Microsoft released patches on February 10, 2026, as part of the February 2026 Patch Tuesday update. Organizations should update to the following minimum builds: Windows 11 24H2 → 10.0.26100.7781, Windows 11 25H2 → 10.0.26200.7781, and Windows Server 2025 → 10.0.26100.32313. As a compensating control, restrict local interactive and remote desktop access to only authorized and necessary users to reduce the attack surface until patching is complete (Microsoft MSRC, Qualys Blog).
The vulnerability was covered as part of broader February 2026 Patch Tuesday roundups by security vendors including Qualys, Rapid7, Sophos, and BleepingComputer, though it did not receive individual spotlight coverage given the absence of active exploitation. SANS ISC and BleepingComputer noted the patch Tuesday release included six zero-days and 58 total flaws, with CVE-2026-21245 categorized among the high-severity but non-actively-exploited issues (BleepingComputer, Sophos Blog, Rapid7 Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."