Executive brief
Windows Error Reporting is a system component that collects and reports application crash information to Microsoft. A heap-based buffer overflow vulnerability in this service allows an authenticated local attacker to execute arbitrary code with elevated system privileges, potentially leading to complete system compromise.
Technical details
A heap-based buffer overflow exists in the Windows Error Reporting service, allowing a local authenticated attacker to cause memory corruption and gain privilege escalation. The vulnerability requires prior authentication or local access to trigger, but does not require user interaction once the attacker has a foothold. An attacker who exploits this flaw can achieve arbitrary code execution with system privileges. Microsoft has assigned this a CVSS v3.1 score of 8.8 and patches are available through the standard security update process.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed