CVE-2026-61355
Windows Sensor Data Service Elevation of Privilege Vulnerability
Description
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowCVE-2026-61355 is a Windows flaw where a logged-in user can crash or corrupt the Windows Sensor Data Service using malformed data, potentially gaining higher administrative rights; most small businesses should patch it soon because it’s reachable by anyone who already has a valid login locally.
CVE-2026-61355 is a local elevation of privilege in the Windows Sensor Data Service caused by improper memory handling (heap buffer overflow / memory corruption) when malformed input is provided by a low-privilege local user with access to the service; the vulnerability is reachable in default configuration.
What to do now
- Check whether your Windows 10, Windows 11, Windows Server 2022, or Windows Server 2025 machines are at or below the affected (not-yet-fixed) build levels for CVE-2026-61355.
- Update each affected device to the first fixed version listed below for your exact Windows version.
- After updating, confirm the OS build number changed to the fixed build and that Windows Sensor Data Service is functioning normally.
- If you cannot patch immediately, restrict who can log on locally and limit local access to the Sensor Data Service so untrusted local users cannot interact with it.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-61355 and every CVE in our database. Create a free account — no credit card required.
Create Free Account