Microsoft Windows WalletService Elevation of Privilege Vulnerability Exploit (CVE-2026-49176)

This module exploits an elevation of privilege vulnerability in Windows WalletService to achieve arbitrary code execution with NT AUTHORITY\\SYSTEM privileges. The exploit performs the following steps: Prepares a controlled Wallet store containing a persisted callback. Temporarily redirects the current user's Documents known folder to the controlled store. Triggers WalletService through the Windows Wallet APIs. Starts a SYSTEM-level CORE Impact agent from the WalletService callback. Restores the original Documents known folder and removes temporary artifacts when possible.
Exploit Platform
Product Name