Junglewise Threat Intelligence

CVE-2024-26169: Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability

CVE-2024-26169 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2024-06-13

Technologies: Microsoft Windows Server 2008, Microsoft Windows, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2019, Microsoft Windows 11, Microsoft Windows Server 2022, Microsoft Windows Server 2016, Microsoft Windows 10. Vendors: Microsoft.

Executive brief

The Microsoft Windows Error Reporting (WER) Service contains an improper privilege management vulnerability. A local attacker with standard user permissions can exploit this flaw to elevate their privileges to SYSTEM level.

Affected products

  • Microsoft Windows 10 up to (excluding) 10.0.10240.20526 (1507), 10.0.14393.6796 (1607), 10.0.17763.5576 (1809), 10.0.19044.4170 (21H2), 10.0.19045.4170 (22H2)
  • Microsoft Windows 11 up to (excluding) 10.0.22000.2836 (21H2), 10.0.22621.3296 (22H2), 10.0.22631.3296 (23H2)
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2016
  • Microsoft Windows Server 2019 up to (excluding) 10.0.17763.5576
  • Microsoft Windows Server 2022 up to (excluding) 10.0.20348.2333, 10.0.25398.763 (23H2)

Timeline

  • 2024-06-13: disclosed
  • 2024-06-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-06-13: patched: Microsoft released security updates to address this vulnerability.
  • exploited: Reported as exploited in the wild.

Related threats