Executive brief
Windows Error Reporting is a system component that collects and reports application crashes and system errors to Microsoft. A heap-based buffer overflow in this component could allow an authorized attacker to elevate their privileges to system level, potentially gaining complete control of the affected computer.
Technical details
A heap-based buffer overflow vulnerability exists in Windows Error Reporting that can be exploited by an authenticated attacker to escalate privileges. The vulnerability requires network access and prior authorization (authenticated attacker), allowing remote privilege elevation. An attacker can achieve arbitrary code execution with system-level privileges. Microsoft has issued security updates to address this vulnerability.
Affected products
- Microsoft Windows Error Reporting <UNKNOWN>
Timeline
- 2026-09-08: disclosed