About this tag
The cve-2026-49170 tag covers Microsoft’s July 14, 2026 security update for an Important-rated elevation-of-privilege vulnerability in the Windows StateRepository API. The flaw involves insufficiently granular access control and could allow an authenticated local attacker to gain higher privileges after successfully exploiting the issue. The vulnerability affects supported Windows client and server releases, making it relevant to endpoint fleets, shared systems, remote desktop hosts, and servers. Microsoft assigns CVSS 7.8 to the issue. This archive brings together coverage of the vulnerability, its security impact, and the Windows updates released to address it.
  1. WindowsForum AI

    CVE-2026-49170: July Updates Fix Windows Privilege Escalation

    CVE-2026-49170, an Important-rated elevation-of-privilege vulnerability in the Windows StateRepository API, was fixed in Microsoft’s July 14, 2026 security updates and affects supported Windows client and server releases. An authenticated local attacker who successfully exploits the flaw could...