[NEU] [hoch] Microsoft Apps: Mehrere Schwachstellen ermöglichen Privilegieneskalation
Ein Angreifer kann mehrere Schwachstellen in Microsoft Authenticator und Microsoft Xbox Gaming Services ausnutzen, um seine Privilegien zu erhöhen.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3241
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-800970.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-586110.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-80097 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58611 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiples vulnérabilités dans les produits Microsoft (09 septembre 2026)cert-fr-avis
- unknownNCSC-2026-0351 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Developer Toolsncsc-nl
- highCVE-2026-80097: Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate …nvd
- highCVE-2026-58611: Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privil…nvd
- highCVE-2026-58611: Xbox Gaming Services Elevation of Privilege Vulnerabilitymsrc
- highCVE-2026-80097: Microsoft Authenticator Elevation of Privilege Vulnerabilitymsrc
Recent advisories for Microsoft Apps
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-57098: Microsoft Remote Desktop App for Windows Information Disclosure Vulnerabilitymsrc · 2026-09-08
- high[NEW] [high] Microsoft Power Apps: Vulnerability enables privilege escalationcert-bund · 2026-08-07
- high[NEW] [high] Microsoft Excel (2016), Office (2019, 2021 and 2024) and 365 Apps: Vulnerability allows code exec…cert-bund · 2026-08-04
- highCVE-2026-58595: Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an u…nvd · 2026-07-14
- highCVE-2026-50356: Concurrent execution using shared resource with improper synchronization ('race condition') in…nvd · 2026-07-14
- highCVE-2026-49784: Concurrent execution using shared resource with improper synchronization ('race condition') in…nvd · 2026-07-14
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] OpenSSH: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10
- high[UPDATE] [hoch] OpenVPN: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] gzip: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10