Description

Microsoft Edge Elevation Service exposes a privileged COM interface that inadequately validates the privileges of the calling process. A standard (non‑administrator) local user can invoke the IElevatorEdge interface method LaunchUpdateCmdElevatedAndWait, causing the service to execute privileged update commands as LocalSystem. This allows a non‑administrator to enable or disable Windows Virtualization‑Based Security (VBS) by modifying protected system registry keys under HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard. Disabling VBS weakens critical platform protections such as Credential Guard, Hypervisor‑protected Code Integrity (HVCI), and the Secure Kernel, resulting in a security feature bypass.

INFO

Published Date :

2026-01-16T21:28:30.158Z

Last Modified :

2026-01-23T01:18:50.043Z

Source :

microsoft
AFFECTED PRODUCTS

The following products are affected by CVE-2026-21223 vulnerability.

Vendors Products
Microsoft
  • Edge Chromium
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-21223.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact