logo

Proof-of-Concept Released for Windows ALPC Privilege Escalation via Error Reporting

ID: e3affc7b-c630-570d-9149-dea15636eda9

STIX ID: report--e3affc7b-c630-570d-9149-dea15636eda9

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-02

Date Updated: 2026-04-22

Author: Divya

...
...

A high-severity (CVSS 7.8) local privilege escalation (CVE-2026-20817) in Windows Error Reporting enables authenticated low-privileged users to spawn WerFault.exe with a SYSTEM token via a crafted ALPC request to SvcElevatedLaunch; a public PoC exists and Microsoft patched the issue in January 2026 — organizations should apply updates immediately or temporarily disable WerSvc and hunt for anomalous WerFault.exe activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.