## https://sploitus.com/exploit?id=95984AE3-71D7-5A60-B078-10C261342CEB
# CVE-2026-49176 SYSTEM Shell PoC
Local privilege-escalation proof of concept for the Windows WalletService
vulnerability fixed in July 2026.
Technical write-up: [CVE-2026-49176 Exploit Development: WalletService to SYSTEM](https://davidcarliez.github.io/blog/cve-2026-49176-walletservice-to-system/).
A standard user creates a Wallet ESE database containing a persisted callback
and redirects their Documents known folder to it. Vulnerable WalletService
opens the database as LocalSystem with persisted callbacks enabled, causing ESE
to load the supplied DLL. The payload starts a command prompt as SYSTEM in the
active desktop session.
## Run
On a vulnerable Windows 11 system, open a non-elevated PowerShell and run:
```powershell
powershell.exe -ExecutionPolicy Bypass -File .\trigger.ps1
```
Alternatively, double-click `run.cmd`. A shell should open and
print `nt authority\system`.
To rebuild the included binaries, install the Visual Studio C++ build tools and
run:
```powershell
powershell.exe -ExecutionPolicy Bypass -File .\build.ps1
```
Tested on Windows 11 25H2 build `26200.8737`.
## Root cause
WalletService resolves `FOLDERID_Documents` while impersonating the caller,
then reverts to LocalSystem before opening `\Wallet\wallet.db`. It
accepts a caller-created database and enables ESE persisted callbacks. Opening
the `Cards` table resolves the callback path stored in the database schema and
loads the specified DLL as SYSTEM.