PoC Exploit Publicly Disclosed: ‘RegPwn’ Flaw Grants SYSTEM Access via Windows Accessibility
ID: 34dc5d3c-765a-5ce5-8e32-a7ee97a77132
STIX ID: report--34dc5d3c-765a-5ce5-8e32-a7ee97a77132
Feed Name: securityonline.info
Threat Score
A recently disclosed Windows local privilege escalation dubbed RegPwn (CVE-2026-24291) exploits incorrect permissions in ATBroker.exe to allow a low-privileged user to force SYSTEM-level arbitrary registry writes via registry symbolic links and an oplock race, enabling replacement of a service ImagePath and SYSTEM code execution; Microsoft has issued a Patch Tuesday fix and the vulnerability carries a CVSS of 7.8.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
