Micropatches released for Windows WalletService Elevation of Privilege (CVE-2026-49176)

July 2026 Windows Updates brought a patch for CVE-2026-49176, a local privilege escalation vulnerability in WalletService service, allowing a regular local user on the computer to elevate themselves to Local System.
The vulnerability was found and reported to Microsoft by Chen Le Qi and Nguyn ng Nguyn with STAR Labs SG. Subsequently, David Carliez published their own technical analysis and proof of concept, which allowed us to reproduce the issue and create patches for legacy Windows systems.
The Vulnerability
The vulnerability is in the Windows WalletService service, which exposes API that allows every local user to request various operations on their Wallet database. One of these operations results in the service (running as Local System) to open user's malicious Wallet database, resulting in user's DLL being loaded and executed.
Microsoft's Patch
Microsoft fixed this issue by effectively cutting off (disabling) five WalletService functions. Note that Windows Wallet is no longer supported.
Our Patch
Our patch is logically identical to Microsoft's with respect to this vulnerability, but we only disabled the one function that contains the vulnerability. The other four functions are not exploitable on their own.
Let's see our patch in action. A low-privileged attacker is logged in to a vulnerable Windows 11 computer. With 0patch disabled, the attacker launches a malicious script that exploits CVE-2026-49176 and pops up a terminal window running as Local System.
With 0patch enabled, the malicious script does not work as it fails to execute the vulnerable WalletService API.
Micropatch Availability
Micropatches were written for the following security-adopted Windows versions:
Windows 11 v22H2 - fully updated
Windows 11 v21H2 - fully updated
Windows 10 v22H2 - fully updated
Windows 10 v21H2 - fully updated
Windows 10 v21H1 - fully updated
Windows 10 v20H2 - fully updated
Windows 10 v2004 - fully updated
Windows 10 v1909 - fully updated
Windows 10 v1809 - fully updated
Windows 10 v1803 - fully updated
Micropatches have already been distributed to, and applied on, all affected online computers with 0patch Agent in PRO or Enterprise accounts (unless Enterprise group settings prevented that).
Vulnerabilities like these get discovered on a regular basis, and attackers know about them all. If you're using Windows that aren't receiving official security updates anymore, 0patch will make sure these vulnerabilities won't be exploited on your computers - and you won't even have to know or care about these things.
We'd like to thank David Carliez for sharing their writeup and proof-of-concept, which allowed us to create patches for Windows versions that are no longer receiving official updates from Microsoft.
If you're new to 0patch, create a free account in 0patch Central, start a free trial, then install and register 0patch Agent. Everything else will happen automatically. No computer reboot will be needed.
Did you know 0patch security-adopted Windows 10 and Office 2016 and 2019 when they went out of support in October 2025, allowing you to keep using them for at least 3 more years (5 years for Windows 10)? Read more about it here and here.
Note that we will soon security-adopt the following products:
Windows 10 22H2 with Extended Security Updates year 1: October 2026
Windows Server 2012 with Extended Security Updates year 3: October 2026
Windows Server 2012 R2 with Extended Security Updates year 3: October 2026
Microsoft Office 2021: October 2026
Windows 11 23H2 (E): November 2026
Windows Server 2016: January 2027
To learn more about 0patch, please visit our Help Center.