logo

‘RegPwn’ Windows Registry Vulnerability Enables Full System Access to Attackers

ID: f802d35a-da27-5655-82a6-ab7f2251342c

STIX ID: report--f802d35a-da27-5655-82a6-ab7f2251342c

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-18

Date Updated: 2026-04-21

Author: Abinaya

...
...

RegPwn (CVE-2026-24291) is a high-severity Windows local privilege escalation that lets low-privileged users obtain SYSTEM by manipulating accessibility feature registry keys copied to HKLM during Secure Desktop operations; an attacker uses an opportunistic lock to pause the copy and swap the target with a symbolic link to write arbitrary SYSTEM-level registry values. Discovered and weaponized by MDSec in internal engagements, Microsoft patched the flaw in Patch Tuesday updates and MDSec published a proof-of-concept on GitHub.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.