HIGH

CVE-2024-26169

Microsoft Windows 10 1507 2024-03-12 CVSS v3.1
CVSS
7.8
KEV

Description

Windows Error Reporting Service Elevation of Privilege Vulnerability

Summary dbcve.org

This is a local privilege escalation vulnerability in the Windows Error Reporting Service (WER). The WER service runs with elevated SYSTEM privileges and could allow a local attacker to gain higher-level system access by exploiting improper privilege validation in the service.

Mitigation

Apply the Microsoft security update for CVE-2024-26169 via Windows Update or by deploying the relevant patch through enterprise patch management systems.

Patch Commit

Weakness (CWE)

CWE-269 Improper Privilege Management

EPSS Score

4.01%
Probability of exploitation in next 30 days
90.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE