Skip to content

Topic

Local Privilege Escalation

A class of security flaws that let a locally authenticated attacker escalate from limited access to root or administrator privileges on a system.

Current stories

securityConfirmed5 publishers

Defender's SYSTEM race is back: ShieldBreak PoC says Microsoft's July fix never held

A researcher claims a 100% reliable bypass of the Malware Protection Engine fix for CVE-2026-50656 on Windows 11 25H2 and Server 2025. There is no second patch to apply.

Perspective Coverage

5 publishers
Builder
Builder 23%
Operator
Operator 65%
Investor
Investor 12%

Reality

Evidence55
Adoption
Insufficient
Hype gap+35
Incentives60
Confidence50
securityConfirmed5 publishers

FalconFlank PoC turns CrowdStrike's macro cleanup into a local privilege escalation

Chaotic Eclipse published working code that abuses Falcon's Office macro removal on fully patched Windows 11 25H2 and Server 2025. It is the fourth endpoint product the researcher has dropped exploit code for, and no CrowdStrike response is on record.

Perspective Coverage

5 publishers
Builder
Builder 36%
Operator
Operator 51%
Investor
Investor 13%

Reality

Evidence70
Adoption
Insufficient
Hype gap+10
Incentives55
Confidence68
securityConfirmed3 publishers

JFrog says a stock Parallels Desktop install hands any local user a root shell

JFrog found that an unprivileged account on a Mac running Parallels Desktop 26.4.0 can reach the root dispatcher over a world-writable socket and run code as uid 0 through argument injection in the appliance installer.

Perspective Coverage

3 publishers
Builder
Builder 34%
Operator
Operator 48%
Investor
Investor 18%

Reality

Evidence80
Adoption42
Hype gap+10
Incentives55
Confidence76