Junglewise Threat Intelligence

CVE-2026-69612: Microsoft Windows Error Reporting absolute path traversal privilege escalation

CVE-2026-69612 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows Error Reporting. Vendors: Microsoft.

Executive brief

Windows Error Reporting is a system service that collects and reports crash and error data to Microsoft. A path traversal vulnerability in this service allows an authorized local user to write files to arbitrary locations on the system, potentially leading to privilege escalation and complete system compromise.

Technical details

The vulnerability is an absolute path traversal flaw in the Windows Error Reporting component that allows an authenticated local attacker to bypass directory restrictions and write files to arbitrary filesystem locations. The attack requires local access and authentication privileges. By exploiting this path traversal, an attacker can overwrite system files or plant malicious files in locations that execute with higher privileges, achieving local privilege escalation. A patch from Microsoft should be available through Windows Update.

Affected products

  • Microsoft Windows Error Reporting <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats