Skip to content
Threat Feed

Tag

Lpe

6 briefs RSS
high advisory

Kernel Local Privilege Escalation Vulnerability CVE-2026-17523

A critical local privilege escalation (LPE) vulnerability, tracked as CVE-2026-17523 and identified as an Expired Pointer Dereference (CWE-825), exists within the kernel, primarily affecting Red Hat Enterprise Linux 8, enabling an unprivileged local user to execute arbitrary code within the kernel, leading to root privileges and full control over the compromised system.

Red Hat Enterprise Linux 8 privilege-escalation kernel-vulnerability linux lpe cve
1t 1c
high advisory

MEmu Android Emulator 9.2.7.0 Local Privilege Escalation

A local privilege escalation vulnerability (CVE-2026-36213) in MEmu Android Emulator 9.2.7.0 allows a low-privileged user to replace the 'MemuService.exe' binary due to insecure NTFS permissions, leading to arbitrary code execution with NT AUTHORITY\SYSTEM privileges upon service restart.

MEmu Android Emulator 9.2.7.0 privilege-escalation windows emulator lpe
2r 2t 1c 4i
high advisory

Cortex MCP Server Untrusted Project Bootstrap Code Execution (CVE-2026-49986)

The Cortex MCP server (`neuro-cortex-memory`) is vulnerable to local arbitrary code execution (CVE-2026-49986) when a user opens an attacker-controlled project in the Claude Code IDE and invokes the `open_visualization` tool, allowing an attacker to execute arbitrary Python code with the victim's local user privileges by manipulating the `CLAUDE_PROJECT_DIR` environment variable.

neuro-cortex-memory <= 3.17.0 +1 rce lpe supply-chain ide python environment-variable
7t
high advisory

Linux Kernel DirtyDecrypt Local Privilege Escalation (CVE-2026-31635)

CVE-2026-31635, dubbed DirtyDecrypt, is a local privilege escalation vulnerability in the Linux kernel's rxrpc subsystem (rxgk component), allowing an unprivileged user to corrupt page cache and achieve arbitrary file writes, leading to root access on kernels 6.10 to 6.13 with CONFIG_RXGK enabled.

Linux Linux_Kernel privilege-escalation lpe linux
2r 1t 1c
high advisory

RegPwn Windows Local Privilege Escalation Vulnerability

RegPwn is a now-fixed local privilege escalation vulnerability in Windows that allowed an attacker to gain elevated privileges.

windows lpe privilege-escalation
2r 1t
high advisory

TVicPort64.sys Arbitrary Physical Memory Mapping LPE

The TVicPort64.sys driver, signed by EnTech Taiwan in 2006, is vulnerable to arbitrary physical memory mapping, enabling local privilege escalation on Windows systems.

TVicPort64.sys lpe byovd privilege-escalation signed-driver
2r 1t