Researchers Disclose ‘RegPwn,’ a Windows Registry Weakness Allowing SYSTEM Access
ID: 08703184-c164-50d8-a181-114fa69d5f33
STIX ID: report--08703184-c164-50d8-a181-114fa69d5f33
Feed Name: GBHackers
Threat Score
Researchers disclosed RegPwn (CVE-2026-24291), a Windows elevation-of-privilege flaw that lets a low-privileged user gain SYSTEM by manipulating registry configurations used by Accessibility features; the attack abuses registry symbolic links and a narrow timing window during Secure Desktop transitions, Microsoft patched affected Windows 10/11/Server versions in March 2026, but public exploit code increases the risk of active misuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
