Executive brief
Windows Error Reporting is a system service that collects and reports crash and error data to Microsoft. A path traversal vulnerability in this service allows an authorized local user to write files to arbitrary locations on the system, potentially leading to privilege escalation and complete system compromise.
Technical details
The vulnerability is an absolute path traversal flaw in the Windows Error Reporting component that allows an authenticated local attacker to bypass directory restrictions and write files to arbitrary filesystem locations. The attack requires local access and authentication privileges. By exploiting this path traversal, an attacker can overwrite system files or plant malicious files in locations that execute with higher privileges, achieving local privilege escalation. A patch from Microsoft should be available through Windows Update.
Affected products
- Microsoft Windows Error Reporting <UNKNOWN>
Timeline
- 2026-09-08: disclosed