-
A threat actor is offering what they describe as a Windows 11 local privilege escalation exploit for sale.
-
The seller claims it grants SYSTEM-level access on Windows 11 25H2 and preview builds, and you don’t need any extra tools or dependencies. The listing also claims the exploit has a 100% probability of success.
-
For now, the exploit has no CVE number or exploit code, and there’s no technical details backing up the claims.

Someone reportedly listed a Windows 11 zero-day exploit for sale on a dark web forum. The seller says it can turn an ordinary local account into full SYSTEM access in just about ten seconds. They claim it works on Windows 11 25H2 and even the latest preview builds, and you don’t need to install any extra software. All this, with a $100,000 price tag.
However, the seller didn’t make the exploit public; only potential buyers will get to see the proof of concept. That leaves the core claims impossible to verify. Currently, there’s no CVE or technical root cause tied to the alleged exploit, and no public exploit sample or independent test confirming it works.
What the Seller Claims
The listing describes a local privilege escalation, or LPE. In other words, an individual who doesn’t have much access on the Windows system might seek to acquire very high privileges.
The seller says the attack can bump a local user or guest account all the way up to NT AUTHORITY\SYSTEM the top privileges you can get on Windows.
The post also claims support for Windows 11 25H2 and preview builds. It does not require any dependencies and requires only about 10 seconds for execution. The seller also makes a claim of a 100% success rate. Those details are still seller claims. A 100% success rate is difficult to verify without the exact build and conditions.
The High Price Isn’t Proof of Validity
A $100,000 price tag isn’t surprising for such listings. But just because that’s the going rate for serious exploits doesn’t mean the zero-day is legit. Attackers usually have to get a foot in the door first, but Windows local privilege escalation bugs are still worth a lot, since they give bad actors an easy path to total control. A reliable LPE can turn a stolen account, malware infection, or limited exploit into a serious compromise.
There is also a real market for high-impact Windows exploits. Zero Day Initiative’s 2026 Pwn2Own Berlin rules offered up to $125,000 for a Windows kernel privilege escalation and $175,000 for a sandbox escape. Those are legitimate research payouts, but they show why a working Windows LPE can command serious money.
Underground sellers have advertised Windows LPEs before. ZeroFox reported a May 2026 Exploit forum listing from the actor Sebastian Pereiro.
Windows-related threats on cybercrime forums extend beyond exploit sales. In another case, a threat actor advertised a Windows malware platform on a cybercrime forum, highlighting the broader underground market for tools targeting Windows users.
That offer sought $160,000 for an alleged Windows server LPE that could raise a standard user to SYSTEM-level access. ZeroFox described the actor as moderately credible based on forum history and prior transactions. That does not validate the new $100,000 offer. It only shows that similar claims and prices have appeared before.
Windows has Seen Real LPE Activity this Year
The timing also matters. Windows has seen many real privilege escalation flaws in 2026. Already, Microsoft addressed two Windows LPE vulnerabilities in their September security update. The first is CVE-2026-81963, which hits the Windows Update Stack. The second, CVE-2026-85880, affects Windows Advanced Local Procedure Call. Both let someone with local access elevate their privileges.
Also, Microsoft released Windows 11 25H2 and 24H updates tagged KB5124008. This means if you’re using any of these versions, your OS build jumps to 26200.9445 or 26100.9445.
In addition, there have been several investigations into Windows Defender privilege escalation during the early part of this year. One vulnerability, called RoguePlanet, or CVE-2026-50656, became public in June.
Another exploit named ShieldBreak supposedly overcame Microsoft’s patch and obtained SYSTEM privilege on Windows 11 25H2. Researchers reported that exploit publicly, making it very different from the private sale described here.
That history shows that SYSTEM-level LPEs on current Windows builds are technically possible. It doesn’t mean that such a $100,000 exploit exists.
The Listing Remains Unverified
The main issue with this listing is the lack of evidence. It has no CVE identifier. No vendor advisory or technical write-up. And no exploit code, crash data, or independent reproducibility tied to the claim. There’s also no way to verify the seller’s claim of 10-second execution time and 100% reliability.
The claim should not be confused with known Windows flaws patched this month. A seller can call an exploit a zero-day without proving it is new.
If this listing turns out to be genuine, the exploit’s worth will be evident because an attacker can leverage LPE to gain system-level access after gaining limited initial access via phishing, malware, stolen credentials, etc. There are no indications, however, at this time that any attackers are exploiting the alleged vulnerability.
For those defending against the threat, the obvious advice would be to ensure that Windows is patched, restrict local accounts, and monitor for signs of privilege escalation. There is currently no CVE number or patch associated with the claims about this LPE. Until something more comes to light, the alleged $100,000 Windows 11 LPE should remain an allegation from the underground market.