Executive brief
The Microsoft Windows Error Reporting (WER) Service contains an improper privilege management vulnerability. A local attacker with standard user permissions can exploit this flaw to elevate their privileges to SYSTEM level.
Affected products
- Microsoft Windows 10 up to (excluding) 10.0.10240.20526 (1507), 10.0.14393.6796 (1607), 10.0.17763.5576 (1809), 10.0.19044.4170 (21H2), 10.0.19045.4170 (22H2)
- Microsoft Windows 11 up to (excluding) 10.0.22000.2836 (21H2), 10.0.22621.3296 (22H2), 10.0.22631.3296 (23H2)
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.5576
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.2333, 10.0.25398.763 (23H2)
Timeline
- 2024-06-13: disclosed
- 2024-06-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-06-13: patched: Microsoft released security updates to address this vulnerability.
- exploited: Reported as exploited in the wild.