CVE-2026-42902 Microsoft PowerToys Elevation of Privilege Vulnerability Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally. EPSS 0.00 CVE-2026-42902 Microsoft US Microsoft Security · 9. 6. 16:00