logo

Windows Error Reporting Vulnerability Exposes Systems to Privilege Escalation, Allowing SYSTEM Access

ID: 28cf45be-b9be-591a-b215-31e33c9f526f

STIX ID: report--28cf45be-b9be-591a-b215-31e33c9f526f

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-27

Date Updated: 2026-04-22

Author: Divya

...
...

Microsoft patched CVE-2026-20817, a critical local privilege escalation in the Windows Error Reporting (WerSvc.dll) service that permitted a low-privileged local attacker to gain SYSTEM via specially crafted ALPC messages and a shared file-mapping buffer; researchers published a functional PoC, Microsoft mitigated the issue by deadcoding the vulnerable function, and Windows Defender detects exploitation attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.