{"id":"CVE-2026-42980","title":"Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.","summary":"Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-122","CWE-191"],"vendor":"microsoft","product":"windows_10_1607","affected":["windows_10_1607 < 10.0.14393.9234","windows_10_1809 < 10.0.17763.8880","windows_10_21h2 < 10.0.19044.7417","windows_10_22h2 < 10.0.19045.7417","windows_11_23h2 < 10.0.22631.7219","windows_11_24h2 < 10.0.26100.8655","windows_11_25h2 < 10.0.26200.8655","windows_11_26h1 < 10.0.28000.2269","windows_server_2012","windows_server_2012 = r2","windows_server_2016 < 10.0.14393.9234","windows_server_2019 < 10.0.17763.8880","windows_server_2022 < 10.0.20348.5256","windows_server_2025 < 10.0.26100.32995"],"patched":["windows_10_1607 10.0.14393.9234","windows_10_1809 10.0.17763.8880","windows_10_21h2 10.0.19044.7417","windows_10_22h2 10.0.19045.7417","windows_11_23h2 10.0.22631.7219","windows_11_24h2 10.0.26100.8655","windows_11_25h2 10.0.26200.8655","windows_11_26h1 10.0.28000.2269","windows_server_2016 10.0.14393.9234","windows_server_2019 10.0.17763.8880","windows_server_2022 10.0.20348.5256","windows_server_2025 10.0.26100.32995"],"published":"2026-06-09","updated":"2026-07-29","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-42980","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42980","label":"secure@microsoft.com"}],"tags":["nvd","exploit-available"],"epss":0.06949,"epssPercentile":0.939,"ingestedAt":"2026-07-29T20:50:14.634Z","exploits":{"github":1,"githubRepos":["https://github.com/G4sp4rCS/CVE-2026-42980-POC"],"checkedAt":"2026-09-21T15:28:55.344Z"},"exploitAvailable":true,"slug":"CVE-2026-42980","body":"## Overview\n\nInteger underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.\n\n## Affected\n\n- `windows_10_1607 < 10.0.14393.9234`\n- `windows_10_1809 < 10.0.17763.8880`\n- `windows_10_21h2 < 10.0.19044.7417`\n- `windows_10_22h2 < 10.0.19045.7417`\n- `windows_11_23h2 < 10.0.22631.7219`\n- `windows_11_24h2 < 10.0.26100.8655`\n- `windows_11_25h2 < 10.0.26200.8655`\n- `windows_11_26h1 < 10.0.28000.2269`\n- `windows_server_2012`\n- `windows_server_2012 = r2`\n- `windows_server_2016 < 10.0.14393.9234`\n- `windows_server_2019 < 10.0.17763.8880`\n- `windows_server_2022 < 10.0.20348.5256`\n- `windows_server_2025 < 10.0.26100.32995`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `windows_10_1607 10.0.14393.9234`\n- `windows_10_1809 10.0.17763.8880`\n- `windows_10_21h2 10.0.19044.7417`\n- `windows_10_22h2 10.0.19045.7417`\n- `windows_11_23h2 10.0.22631.7219`\n- `windows_11_24h2 10.0.26100.8655`\n- `windows_11_25h2 10.0.26200.8655`\n- `windows_11_26h1 10.0.28000.2269`\n- `windows_server_2016 10.0.14393.9234`\n- `windows_server_2019 10.0.17763.8880`\n- `windows_server_2022 10.0.20348.5256`\n- `windows_server_2025 10.0.26100.32995`","depth":"midnight","depthScore":56,"depthScoreParts":{"impact":42.9,"likelihood":1.4,"exploitation":12,"ransomware":0},"changes":[{"seq":5213,"id":"CVE-2026-42980","ts":1788887253772,"field":"exploit_available","old":"false","new":"true"},{"seq":4096,"id":"CVE-2026-42980","ts":1788886369660,"field":"exploit_available","old":"true","new":"false"},{"seq":2873,"id":"CVE-2026-42980","ts":1788883035949,"field":"exploit_available","old":"false","new":"true"},{"seq":1902,"id":"CVE-2026-42980","ts":1788882439087,"field":"exploit_available","old":"true","new":"false"},{"seq":996,"id":"CVE-2026-42980","ts":1788881873434,"field":"exploit_available","old":"false","new":"true"}]}