CVE-2026-59133
Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability
Description
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.
In plain language
AI Act nowCVE-2026-59133 is an elevation-of-privilege flaw in Microsoft High Performance Computing (HPC) Pack where someone with a low-privilege network account can take higher control over the software; if you run this on a network with user accounts, you should act now.
Authenticated low-privilege users can exploit a Microsoft High Performance Computing (HPC) Pack process-handling weakness to gain unauthorized higher-level permissions via network access, enabling full control of the affected HPC Pack software.
What to do now
- Check whether your organization runs Microsoft High Performance Computing (HPC) Pack and identify its installed version.
- If the version is older than 2.0.1193.0, plan an upgrade to 2.0.1193.0 as the fix.
- If you can’t upgrade immediately, restrict who can reach HPC Pack from the network (limit access to only required, trusted accounts and hosts).
- Review account access: ensure the minimum necessary privileges for accounts that can authenticate to the system running HPC Pack.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-59133 and every CVE in our database. Create a free account — no credit card required.
Create Free Account