Untrusted Pointer Dereference in Microsoft Windows and Windows Server - CVE-2026-83498
Published: September 9, 2026
Vulnerability details
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave when dereferencing an untrusted pointer. A local user can exploit the untrusted pointer dereference to elevate privileges.
Successful exploitation could leak data from the target enclave or execute code in the context of the target enclave.
Affected software
Windows Server
How to mitigate CVE-2026-83498
Windows Server - update to 2025 10.0.26100.33438