Metrics
Affected Vendors & Products
Thu, 26 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Sun, 22 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Microsoft Edge Elevation Service exposes a privileged COM interface that inadequately validates the privileges of the calling process. A standard (non‑administrator) local user can invoke the IElevatorEdge interface method LaunchUpdateCmdElevatedAndWait, causing the service to execute privileged update commands as LocalSystem. This allows a non‑administrator to enable or disable Windows Virtualization‑Based Security (VBS) by modifying protected system registry keys under HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard. Disabling VBS weakens critical platform protections such as Credential Guard, Hypervisor‑protected Code Integrity (HVCI), and the Secure Kernel, resulting in a security feature bypass. | Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally. |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 16 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 16 Jan 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Microsoft Edge Elevation Service exposes a privileged COM interface that inadequately validates the privileges of the calling process. A standard (non‑administrator) local user can invoke the IElevatorEdge interface method LaunchUpdateCmdElevatedAndWait, causing the service to execute privileged update commands as LocalSystem. This allows a non‑administrator to enable or disable Windows Virtualization‑Based Security (VBS) by modifying protected system registry keys under HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard. Disabling VBS weakens critical platform protections such as Credential Guard, Hypervisor‑protected Code Integrity (HVCI), and the Secure Kernel, resulting in a security feature bypass. | |
| Title | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | |
| First Time appeared |
Microsoft
Microsoft edge Chromium |
|
| Weaknesses | CWE-269 | |
| CPEs | cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft edge Chromium |
|
| References |
|
Status: PUBLISHED
Assigner: microsoft
Published: 2026-01-16T21:28:30.158Z
Updated: 2026-02-26T14:44:46.346Z
Reserved: 2025-12-11T21:02:05.732Z
Link: CVE-2026-21223
Updated: 2026-01-16T21:50:19.043Z
Status : Modified
Published: 2026-01-16T22:16:25.983
Modified: 2026-02-22T17:16:54.310
Link: CVE-2026-21223
No data.