Vulnerability record · CVE-2024-26169 · published 12 March 2024
CVE-2024-26169: Windows Error Reporting Service privilege escalation flaw
Microsoft · Windows 10 1507
CVE-2024-26169 is an improper privilege management vulnerability in the Windows Error Reporting Service, classified under CWE-269. A local attacker with low privileges can exploit it to gain elevated rights on affected Windows client and server versions. It matters because Microsoft patched it and CISA added it to the Known Exploited Vulnerabilities catalog, indicating real-world abuse.
Description
Windows Error Reporting Service Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with local low-privilege access, confirmed KEV listing and known ransomware campaign use make this a high-priority patch despite the local attack vector.
What it is
CVE-2024-26169 is an improper privilege management vulnerability in the Windows Error Reporting Service, classified under CWE-269. A local attacker with low privileges can exploit it to gain elevated rights on affected Windows client and server versions. It matters because Microsoft patched it and CISA added it to the Known Exploited Vulnerabilities catalog, indicating real-world abuse.
Impact
An attacker gains full compromise of confidentiality, integrity and availability at the elevated privilege level, effectively SYSTEM on the host. This enables credential theft, persistence and lateral movement from an already-established low-privileged foothold.
Attack surface
The CVSS vector AV:L/AC:L/PR:L/UI:N/S:U indicates the flaw is reached locally, requires low privileges and no user interaction. No network vector or authentication bypass is described in the record.
Exploitation
CISA added this to the KEV catalog on 2024-06-13 with a due date of 2024-07-04 and flags known ransomware campaign use. EPSS 30-day probability is 0.04014 (90th percentile), and the only references are the Microsoft patch advisory and the CISA KEV entry.
What to do
- Apply the Microsoft security update for CVE-2024-26169 on all affected Windows client and server builds, prioritizing internet-facing and high-value hosts.
- If patching is not possible, follow CISA guidance to discontinue use of the affected product.
- Restrict local interactive logon and service account privileges to the minimum needed, since exploitation requires a low-privileged local foothold.
- Monitor for and remove unpatched or end-of-life Windows builds listed as affected, including Windows Server 2008 and 2012.
- Treat any host with this CVE as potentially compromised and hunt for post-exploitation activity, given the KEV ransomware flag.
Detection
- Audit Windows Error Reporting Service (WerSvc) process creation and unexpected child processes spawning from it.
- Monitor for privilege escalation indicators such as new SYSTEM-level processes or service creation originating from low-privileged user contexts.
- Correlate local logon events with subsequent high-integrity process starts on hosts that have not yet applied the March 2024 patch.
- Review EDR telemetry for known exploitation artifacts tied to CVE-2024-26169 and for ransomware precursor behavior on affected endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-26169 to the Known Exploited Vulnerabilities catalog on 13 June 2024 as "Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Federal deadline 4 July 2024.
Affected products
14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26169 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26169 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-26169 | US Government Resource |
Track CVE-2024-26169 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-26169), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.