Microsoft Windows WalletService Privilege Escalation Vulnerability
Vulnerability
A use-after-free vulnerability has been identified in the Windows WalletService, allowing an authorized attacker to locally elevate privileges. This vulnerability arises from improper memory management, which can be exploited to gain higher-level permissions.
Impact
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain SYSTEM privileges.
Remediation
Users can apply the security update for this vulnerability, which is available through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5082198 for Windows Server 2016, KB5082063 for Windows Server 2025, KB5082060 for Windows Server 2022 23H2 Edition, KB5082142 for Windows Server 2022, KB5082123 for Windows Server 2019, and KB5082198 for Windows Server 2016 (Server Core installation).
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
