Executive brief
A security vulnerability exists in Windows Error Reporting, a built-in feature that captures and sends diagnostic data to Microsoft when software crashes. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to bypass security restrictions, access sensitive data, or install malicious software.
Technical details
A local privilege escalation vulnerability exists in the Windows Error Reporting (WER) component due to improper handling of insufficient permissions (CWE-280). An attacker with low-privileged local access can exploit this flaw to gain SYSTEM-level privileges. The attack vector is local and requires no user interaction. Microsoft has released security updates to address this issue across multiple versions of Windows 10, Windows 11, and Windows Server. Security engineers should verify that systems are updated to the builds specified in the vendor advisory to mitigate the risk of unauthorized privilege elevation.
Affected products
- Microsoft Windows 10 21H2, 22H2
- Microsoft Windows 11 23H2, 24H2, 25H2
- Microsoft Windows Server 2022 Standard, 23H2
- Microsoft Windows Server 2025 Standard
Timeline
- 2026-01-13: advisory: Initial advisory published by Microsoft and NVD.
- 2026-05-26: other: NVD record updated with additional references and enrichment data.