This allows a non‑administrator to enable or disable Windows Virtualization‑Based Security (VBS) by modifying protected system registry keys under HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard. Disabling VBS weakens critical platform protections such as Credential Guard, Hypervisor‑protected Code Integrity (HVCI), and the Secure Kernel, resulting in a security feature bypass.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 16 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 16 Jan 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Microsoft Edge Elevation Service exposes a privileged COM interface that inadequately validates the privileges of the calling process. A standard (non‑administrator) local user can invoke the IElevatorEdge interface method LaunchUpdateCmdElevatedAndWait, causing the service to execute privileged update commands as LocalSystem. This allows a non‑administrator to enable or disable Windows Virtualization‑Based Security (VBS) by modifying protected system registry keys under HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard. Disabling VBS weakens critical platform protections such as Credential Guard, Hypervisor‑protected Code Integrity (HVCI), and the Secure Kernel, resulting in a security feature bypass. | |
| Title | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | |
| First Time appeared |
Microsoft
Microsoft edge Chromium |
|
| Weaknesses | CWE-269 | |
| CPEs | cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft edge Chromium |
|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-01-16T21:50:24.474Z
Reserved: 2025-12-11T21:02:05.732Z
Link: CVE-2026-21223
Updated: 2026-01-16T21:50:19.043Z
Status : Received
Published: 2026-01-16T22:16:25.983
Modified: 2026-01-16T22:16:25.983
Link: CVE-2026-21223
No data.
OpenCVE Enrichment
No data.