Junglewise Threat Intelligence

CVE-2026-20817: Microsoft Windows Error Reporting privilege escalation

CVE-2026-20817 · Severity: high · CVSS 7.8 · Published 2026-01-13

Technologies: Microsoft Windows 11 24h2, Microsoft Windows Server 2022 23h2, Microsoft Windows 10 22h2, Microsoft Windows 11 23h2, Microsoft Windows Server 2025, Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows 10 21h2, Microsoft Windows 11 25h2, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Windows Error Reporting, a built-in feature that captures and sends diagnostic data to Microsoft when software crashes. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to bypass security restrictions, access sensitive data, or install malicious software.

Technical details

A local privilege escalation vulnerability exists in the Windows Error Reporting (WER) component due to improper handling of insufficient permissions (CWE-280). An attacker with low-privileged local access can exploit this flaw to gain SYSTEM-level privileges. The attack vector is local and requires no user interaction. Microsoft has released security updates to address this issue across multiple versions of Windows 10, Windows 11, and Windows Server. Security engineers should verify that systems are updated to the builds specified in the vendor advisory to mitigate the risk of unauthorized privilege elevation.

Affected products

  • Microsoft Windows 10 21H2, 22H2
  • Microsoft Windows 11 23H2, 24H2, 25H2
  • Microsoft Windows Server 2022 Standard, 23H2
  • Microsoft Windows Server 2025 Standard

Timeline

  • 2026-01-13: advisory: Initial advisory published by Microsoft and NVD.
  • 2026-05-26: other: NVD record updated with additional references and enrichment data.

References

Related threats