CVE-2026-41097
Microsoft Windows 10 21H2 ≤ 10.0.19044.7291
Raw vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2026-41097 is a medium-severity Reliance on Component That is Not Updateable (CWE-1329) vulnerability in Microsoft Windows 10 21H2. Its CVSS base score is 6.7 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked in the top 30% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SA-22 (Unsupported System Components) — see the control section below for these in your framework.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-29685
Vulnerability Data
Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Replacing components when vendor support ends directly stops reliance on non-updateable parts that cannot receive patches.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Directly addresses replacing or removing software that cannot be maintained via updates or patches.
Directly addresses replacing hardware components that lack needed security capabilities or cannot be updated.
Lifecycle management explicitly requires planning for updates or replacement of components that cannot be patched.
Supplier risk assessment can identify non-updateable components before acquisition but does not prevent their use inside the product.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Supplier agreements can stipulate patchability or end-of-life support, yet the weakness is rooted in product architecture rather than contractual clauses.
ICT supply-chain management can influence component selection toward maintainable ones, but does not guarantee technical updateability.
Supplier-relationship controls can require vendors to provide updateable components, but do not directly mandate component design.
Secure-SDLC practices encourage selection of maintainable components, but the weakness may still arise from third-party or legacy choices.
Change-management processes can plan for component replacement, yet cannot eliminate the inherent non-updateability of an already-deployed component.
Vulnerability-management processes can detect and drive replacement of non-updateable components, but cannot retroactively make them patchable.