Out-of-bounds read in Endpoint Privilege Management for Windows - CVE-2026-40144
Published: August 19, 2026
Vulnerability identifier: #VU144322
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40144
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to execute arbitrary code in kernel mode.
The vulnerability exists due to out-of-bounds read in a kernel-mode component when processing input. A local user can trigger memory corruption to execute arbitrary code in kernel mode.
Exploitation requires local access to the endpoint.
Affected software
Endpoint Privilege Management for Windows
How to mitigate CVE-2026-40144
Install security update from vendor's website.
Endpoint Privilege Management for Windows - update to 26.1.2