CVE-2026-21223
Microsoft Edge Elevation Service exposes a privileged COM interface that inadequately validates the privileges of the calling process. A standard (non‑administrator) local user can invoke the IElevatorEdge interface method LaunchUpdateCmdElevatedAndWait, causing the service to execute privileged update commands as LocalSystem. This allows a non‑administrator to enable or disable Windows Virtualization‑Based Security (VBS) by modifying protected system registry keys under HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard. Disabling VBS weakens critical platform protections such as Credential Guard, Hypervisor‑protected Code Integrity (HVCI), and the Secure Kernel, resulting in a security feature bypass.
EPSS 0.03% · 8.4th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft Edge (Chromium-based) | 1.0.0.0, 1.0.0.0 |
| microsoft | edge_chromium | 0, 1.0.0.0, 0 |
Exploit Intelligence
- https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1 (msrc)
- CIRCL seen: CVE-2026-21223 (circl-sighting)
- CIRCL seen: CVE-2026-21223 (circl-sighting)
- CIRCL seen: CVE-2026-21223 (circl-sighting)
- Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability (circl)
Timeline
- Jan 13, 2026 CVE Published
- Jan 16, 2026 PoC Published
- Jan 17, 2026 EPSS Score
- Jan 17, 2026 PoC Published
- Jan 19, 2026 PoC Published
- Jan 20, 2026 EPSS Score
- Jan 23, 2026 EPSS Score
- Jan 26, 2026 EPSS Score
- Jan 28, 2026 EPSS Score
- Jan 31, 2026 EPSS Score
- Feb 3, 2026 EPSS Score
- Feb 6, 2026 EPSS Score
References
- Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-21223 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0899 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0900 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0903 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0906 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0907 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0908 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0905 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0901 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0904 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0902 advisory