Out-of-bounds read in Endpoint Privilege Management for Windows - CVE-2026-40144

 

Out-of-bounds read in Endpoint Privilege Management for Windows - CVE-2026-40144

Published: August 19, 2026


Vulnerability identifier: #VU144322
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40144
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code in kernel mode.

The vulnerability exists due to out-of-bounds read in a kernel-mode component when processing input. A local user can trigger memory corruption to execute arbitrary code in kernel mode.

Exploitation requires local access to the endpoint.


Affected software

Endpoint Privilege Management for Windows

How to mitigate CVE-2026-40144

Install security update from vendor's website.

Endpoint Privilege Management for Windows - update to 26.1.2

External References

Related Security Bulletins