logo

PoC Exploit Publicly Disclosed: ‘RegPwn’ Flaw Grants SYSTEM Access via Windows Accessibility

ID: 34dc5d3c-765a-5ce5-8e32-a7ee97a77132

STIX ID: report--34dc5d3c-765a-5ce5-8e32-a7ee97a77132

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-18

Date Updated: 2026-04-23

Author: Ddos

...
...

A recently disclosed Windows local privilege escalation dubbed RegPwn (CVE-2026-24291) exploits incorrect permissions in ATBroker.exe to allow a low-privileged user to force SYSTEM-level arbitrary registry writes via registry symbolic links and an oplock race, enabling replacement of a service ImagePath and SYSTEM code execution; Microsoft has issued a Patch Tuesday fix and the vulnerability carries a CVSS of 7.8.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.