Micropatches released for "GreenPlasma" Windows Collaborative Translation Framework Elevation of Privilege (CVE-2026-45586)

June 2026 Windows Updates brought a patch for CVE-2026-45586, a local privilege escalation vulnerability in Windows Collaborative Translation Framework, allowing a local unprivileged attacker to execute arbitrary code as Local System.
The vulnerability was found by security researcher Nightmare-Eclipse, who published a (now deleted) proof-of-concept. This POC allowed us to reproduce the issue and create patches for legacy Windows systems.
The Vulnerability
Several Text Services Framework processes that always run as Local System (e.g., consent.exe, the dialog that asks the user for approval or credentials upon elevation) employ a named memory section with a fixed name, which a malicious local process can redirect to some other section using symbolic links for Windows objects. Consequently, the attacker gains full access to the content of the section, which can be exploited for arbitrary code execution as Local System.
Microsoft's Patch
Microsoft fixed this issue by loading the section without honoring symbolic links.
Our Patch
Our patch is logically identical to Microsoft's.
Micropatch Availability
Micropatches were written for the following security-adopted Windows versions:
Windows 11 v22H2 - fully updated
Windows 11 v21H2 - fully updated
Windows 10 v22H2 - fully updated
Windows 10 v21H2 - fully updated
Windows 10 v21H1 - fully updated
Windows 10 v20H2 - fully updated
Windows 10 v2004 - fully updated
Windows 10 v1909 - fully updated
Windows 10 v1809 - fully updated
Windows 10 v1803 - fully updated
Windows 7 - fully updated with no ESU, with ESU 1, ESU 2 or ESU 3
Windows Server 2008 R2 - fully updated with no ESU, with ESU 1, ESU 2, ESU 3 or ESU 4
Windows Server 2012 - fully updated with no ESU, with ESU 1 or ESU 2
Windows Server 2012 R2 - fully updated with no ESU, with ESU 1 or ESU 2
Micropatches have already been distributed to, and applied on, all affected online computers with 0patch Agent in PRO or Enterprise accounts (unless Enterprise group settings prevented that).
Vulnerabilities like these get discovered on a regular basis, and attackers know about them all. If you're using Windows that aren't receiving official security updates anymore, 0patch will make sure these vulnerabilities won't be exploited on your computers - and you won't even have to know or care about these things.
If you're new to 0patch, create a free account in 0patch Central, start a free trial, then install and register 0patch Agent. Everything else will happen automatically. No computer reboot will be needed.
Did you know 0patch security-adopted Windows 10 and Office 2016 and 2019 when they went out of support in October 2025, allowing you to keep using them for at least 3 more years (5 years for Windows 10)? Read more about it here and here.
Note that we will soon security-adopt the following products:
Windows 10 22H2 with Extended Security Updates year 1: October 2026
Windows Server 2012 with Extended Security Updates year 3: October 2026
Windows Server 2012 R2 with Extended Security Updates year 3: October 2026
Windows Office 2021: October 2026
Windows 11 23H2 (E): November 2026
Windows Server 2016: January 2027
To learn more about 0patch, please visit our Help Center.