WalletService Privilege Escalation Flaw Allows Attackers Full Control of Windows Systems
ID: 9acc52e0-419f-52fd-9b16-ba830bed031e
STIX ID: report--9acc52e0-419f-52fd-9b16-ba830bed031e
Feed Name: cybersecurityNews.com
**CVE-2026-49176 — WalletService local privilege escalation:** Microsoft patched a flaw in WalletService where the service uses a user's Documents path to locate wallet.db then stops impersonating the user before opening that database, allowing a standard user to supply an ESE database with a persisted callback that loads attacker-controlled DLL code into a SYSTEM svchost process; Microsoft mitigated the issue with WalletServiceRedirectionGuard and recommends applying updates and monitoring for unexpected wallet.db access, svchost DLL loads from user-writable locations, and short-lived SYSTEM interactive shells.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
