You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2026-32170
About this tag
CVE-2026-32170 is a Windows Rich Text Edit Control elevation-of-privilege vulnerability disclosed by Microsoft in the May 12, 2026 Patch Tuesday security update. The vulnerability affects Windows systems that include the Rich Edit component, a shared building block used by many applications. While not as flashy as a wormable network bug, this platform-level flaw expands the everyday Windows attack surface because the component sits beneath commonly used software. Discussions on WindowsForum cover the technical details, affected systems, and mitigation strategies for this security update.
Microsoft disclosed CVE-2026-32170, a Windows Rich Text Edit Control elevation-of-privilege vulnerability, in its May 12, 2026 Security Update Guide as part of the monthly Patch Tuesday release affecting Windows systems that include the Rich Edit component. The important word is not “rich,” and...