#VU121637 Improper privilege management in Microsoft Edge - CVE-2026-21223
Published: January 16, 2026
Microsoft Edge
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due Microsoft Edge Elevation Service exposes a privileged COM interface that inadequately validates the privileges of the calling process. A standard (non‑administrator) local user can invoke the IElevatorEdge interface method LaunchUpdateCmdElevatedAndWait, causing the service to execute privileged update commands as LocalSystem.