Proof-of-Concept Released for Windows ALPC Privilege Escalation via Error Reporting
ID: e3affc7b-c630-570d-9149-dea15636eda9
STIX ID: report--e3affc7b-c630-570d-9149-dea15636eda9
Feed Name: GBHackers
Threat Score
A high-severity (CVSS 7.8) local privilege escalation (CVE-2026-20817) in Windows Error Reporting enables authenticated low-privileged users to spawn WerFault.exe with a SYSTEM token via a crafted ALPC request to SvcElevatedLaunch; a public PoC exists and Microsoft patched the issue in January 2026 — organizations should apply updates immediately or temporarily disable WerSvc and hunt for anomalous WerFault.exe activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
