‘RegPwn’ Windows Registry Vulnerability Enables Full System Access to Attackers
ID: f802d35a-da27-5655-82a6-ab7f2251342c
STIX ID: report--f802d35a-da27-5655-82a6-ab7f2251342c
Feed Name: cybersecurityNews.com
RegPwn (CVE-2026-24291) is a high-severity Windows local privilege escalation that lets low-privileged users obtain SYSTEM by manipulating accessibility feature registry keys copied to HKLM during Secure Desktop operations; an attacker uses an opportunistic lock to pause the copy and swap the target with a symbolic link to write arbitrary SYSTEM-level registry values. Discovered and weaponized by MDSec in internal engagements, Microsoft patched the flaw in Patch Tuesday updates and MDSec published a proof-of-concept on GitHub.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
