CVE-2026-20817PoC(microsoft / windows_10_21h2)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_10_21h2 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-280

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_21h2
  • windows_10_22h2
  • windows_11_23h2
  • windows_11_24h2

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 43 mentions across 19 observed days
  • Momentum state: declining

What's happening

  • Exploit tool or code specified in 13 signals
  • PoC mentioned or linked in 23 signals
  • Patch or workaround mentioned in 20 signals
  • Technical details provided in 34 signals
  • Disclosure: 9 classified signals
  • Peaked 5d ago at 13 mentions (2026-03-27); latest day: 1
  • 43 total mentions across 19 days

Affected systems

Vendors
Products
windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_server_2022windows_server_2022_23h2windows_server_2025

Deep dive

Activity timeline43 mentions / 19d
0371013Mentions · 2026-02-04: 1Mentions · 2026-02-07: 1Mentions · 2026-02-08: 1Mentions · 2026-02-10: 5Mentions · 2026-02-11: 1Mentions · 2026-02-18: 1Mentions · 2026-02-19: 5Mentions · 2026-02-20: 1Mentions · 2026-02-27: 1Mentions · 2026-03-02: 2Mentions · 2026-03-03: 4Mentions · 2026-03-09: 1Mentions · 2026-03-22: 1Mentions · 2026-03-27: 13Mentions · 2026-03-28: 1Mentions · 2026-03-31: 1Mentions · 2026-04-02: 1Mentions · 2026-04-08: 1Mentions · 2026-04-17: 1PoC Mentioned / Linked · 2026-02-04: 1PoC Mentioned / Linked · 2026-02-07: 1PoC Mentioned / Linked · 2026-02-10: 1PoC Mentioned / Linked · 2026-02-18: 1PoC Mentioned / Linked · 2026-02-19: 4PoC Mentioned / Linked · 2026-02-27: 1PoC Mentioned / Linked · 2026-03-02: 2PoC Mentioned / Linked · 2026-03-03: 3PoC Mentioned / Linked · 2026-03-09: 1PoC Mentioned / Linked · 2026-03-27: 7PoC Mentioned / Linked · 2026-04-08: 1Exploit Tool / Code · 2026-02-19: 3Exploit Tool / Code · 2026-02-27: 1Exploit Tool / Code · 2026-03-03: 2Exploit Tool / Code · 2026-03-27: 6Exploit Tool / Code · 2026-04-08: 1Patch / Workaround · 2026-02-04: 1Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-02-11: 1Patch / Workaround · 2026-03-02: 2Patch / Workaround · 2026-03-03: 2Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-22: 1Patch / Workaround · 2026-03-27: 8Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-17: 1Technical Details · 2026-02-04: 1Technical Details · 2026-02-07: 1Technical Details · 2026-02-10: 3Technical Details · 2026-02-11: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-19: 4Technical Details · 2026-02-27: 1Technical Details · 2026-03-02: 1Technical Details · 2026-03-03: 4Technical Details · 2026-03-09: 1Technical Details · 2026-03-22: 1Technical Details · 2026-03-27: 11Technical Details · 2026-03-28: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-08: 102-0402-0702-0802-1002-1102-1802-1902-2002-2703-0203-0303-0903-2203-2703-2803-3104-0204-0804-17
Signal classification5 categories
PoC
1944.2%
Disclosure
920.9%
Patch
614.0%
General
511.6%
Exploit
49.3%
Referenced assets31 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-041
PoC1
2026-02-071
PoC1
2026-02-081
General1
2026-02-105
Disclosure3General1PoC1
2026-02-111
Patch1
2026-02-181
PoC1
2026-02-195
Exploit1General1PoC3
2026-02-201
General1
2026-02-271
Exploit1
2026-03-022
PoC2
2026-03-034
Patch1PoC3
2026-03-091
PoC1
2026-03-221
Disclosure1
2026-03-2713
Disclosure4Exploit1General1Patch1PoC6
2026-03-281
Patch1
2026-03-311
Disclosure1
2026-04-021
Patch1
2026-04-081
Exploit1
2026-04-171
Patch1
Full discourse20 posts
  • Moonbeom(Daniel)@krNeoTra
    PoC

    Exploit Demo & Analysis Article by 78ResearchLab(@78_lab) CVE-2026-20817 : Windows Error Reporting(WER) Service Elevation of Privilege Vulnerability https://blog.78researchlab.com/2ffdb461-3e5b-80ae-a5e0-e1e24626fe02?fbclid=IwY2xjawPyaVFleHRuA2FlbQIxMQBzcnRjBmFwcF9pZBAyMjIwMzkxNzg4MjAwODkyAAEeKR35FRmuH-h0HY5-prT7c2udxf3uCn-T8JIXF7rkQn3VA-iVUPTwkcPBvZc_aem_G7scfPxjD1IAkyEsEvWa9Q #CVE_2026_20817 #LPE #Windows https://t.co/KGBVT8D0mb

    Post summary

    The tweet announces a PoC and analysis article for CVE-2026-20817, linking to the detailed post, but does not mention active exploitation, patches, or a specific exploit tool.

    451019211312.9K
    1.0K followersView on X
  • Co11ateral@co11ateral
    Exploit

    CVE-2026-20817 Windows Error Reporting ALPC Elevation of Privilege - Proof-of-Concept exploit demonstrating local privilege escalation via WER service https://github.com/oxfemale/CVE-2026-20817 #dfir #redteam #blueteam #poc #windows #Pentesting

    Post summary

    A proof‑of‑concept exploit for CVE‑2026‑20817 targeting Windows Error Reporting via ALPC is available on GitHub, demonstrating local privilege escalation.

    222079523.2K
    1.3K followersView on X
  • Germán Fernández@1ZRR4H
    Exploit

    http://67.215.232[.]25:1337/ #opendir 🔎 → CVE-2026-20817: Windows Error Reporting (WER) ALPC Privilege Escalation + Rubeus + RoguePotato + SharpSuccessor + SweetPotato + RogueOxidResolver https://t.co/OZW5X86GF5

    Post summary

    The post announces CVE‑2026‑20817 with a linked PoC and highlights multiple exploitation tools, indicating the vulnerability’s exploitability.

    019093367.9K
    38.1K followersView on X
  • blueblue@piedpiper1616
    PoC

    GitHub - oxfemale/CVE-2026-20817: Windows Error Reporting ALPC Elevation of Privilege (CVE-2026-20817) - Proof-of-Concept exploit demonstrating local privilege escalation via WER service. - https://github.com/oxfemale/CVE-2026-20817?tab=readme-ov-file

    Post summary

    A GitHub repository hosts a proof‑of‑concept exploit for CVE‑2026‑20817, demonstrating local privilege escalation through Windows Error Reporting's ALPC interface.

    014030222.6K
    5.5K followersView on X
  • PatchPoint.Official@_patchpoint_
    PoC

    We released a demo video for the CVE-2026-20817 Windows Error Reporting Service Elevation of Privilege Vulnerability, patched by Microsoft in Jan 2026. https://youtu.be/5YzTgyPQd4M Watch the video and subscribe to our private vulnerability PoC and detailed report service at http://Patchpoint.io. #Windows #Microsoft #WindowsErrorReporting #WER #Vulnerability #CVE_2026_20817

    Post summary

    A demo video demonstrating the CVE-2026-20817 elevation‑of‑privilege flaw was released, confirming the vulnerability and providing a PoC, while Microsoft already issued a patch.

    04021151.9K
    428 followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit 1⃣. CVE-2026-2441: https://github.com/huseyinstif/CVE-2026-2441-PoC Google Chrome Blink RCE 2⃣. CVE-2026-27896: https://dev.to/cverports/cve-2026-27896-case-insensitive-chaos-bypassing-security-controls-in-mcp-go-sdk-jag Bypassing Security Controls in MCP Go SDK 3⃣. CVE-2026-20841: https://github.com/tangent65536/CVE-2026-20841 Windows Notepad RCE 4⃣. CVE-2026-20817: https://github.com/oxfemale/CVE-2026-20817 Windows Error Reporting ALPC Privilege Escalation 5⃣. CVE-2026-25253: https://github.com/ethiack/moltbot-1click-rce Clawdbot/Moltbot/OpenClaw One-click RCE

    Post summary

    The post lists five CVEs along with GitHub links to functional exploit code for each, highlighting RCE and privilege escalation vulnerabilities.

    0202014708
    3.1K followersView on X
  • Gray Hats@the_yellow_fall
    PoC

    Clément Labro releases a public PoC for CVE-2026-20817, a critical Windows LPE flaw in the WER service. Patch now to prevent SYSTEM-level hijacking. #WindowsSecurity #LPE #CVE #GitHub #PoC #CyberSecurity #InfoSec #Microsoft #Exploit #PrivEsc #Windows11 https://securityonline.info/windows-error-reporting-lpe-cve-2026-20817-public-poc-exploit/ https://t.co/GGzNMKuCGM

    Post summary

    A public PoC for CVE-2026-20817, a critical LPE flaw in Windows WER, has been released and a patch is now available to mitigate the SYSTEM‑level hijacking risk.

    0301581.6K
    11.0K followersView on X
  • yousukezan@yousukezan
    PoC

    Windowsのエラー報告機能に重大な権限昇格の脆弱性が見つかり、公開されたPoCにより悪用リスクが急上昇している。一般ユーザーからSYSTEM権限への昇格が可能な危険な問題である。 この脆弱性はCVE-2026-20817として報告され、WER(Windows Error Reporting)サービス内のWerSvc.dllに存在する。特にSvcElevatedLaunch関数の不備により、細工されたALPCメッセージを送信することで権限昇格が成立する。 攻撃者は\WindowsErrorReportingServicePortに接続し、ファイルマッピングオブジェクトを含むリクエストを送ることで、WerFault.exeをSYSTEM権限で起動させることができる。実行ファイル自体は固定だが、コマンドライン引数は任意に制御可能である。 さらにプロセスの親子関係を偽装する仕組みもあり、検知を困難にする工夫が施されている。PoCは完全なコード実行には至らないものの、攻撃基盤として十分な内容となっている。 Microsoftは2026年1月の更新で当該機能を無効化する形で修正しており、未適用環境では悪用の可能性が高い。全端末へのパッチ適用確認が重要となる。 https://securityonline.info/windows-error-reporting-lpe-cve-2026-20817-public-poc-exploit/

    Post summary

    A publicly disclosed PoC and detailed privilege‑escalation method for CVE‑2026‑20817 are presented, a disable‑patch was released in January 2026, and no active exploitation has yet been reported.

    0301351.3K
    12.6K followersView on X
  • 0patch@0patch
    Patch

    Micropatches released for Windows Error Reporting Service Elevation of Privilege Vulnerability (CVE-2026-20817) https://blog.0patch.com/2026/04/micropatches-released-for-windows-error.html https://t.co/s9pNkqQQUf

    Post summary

    Micropatches have been released to remediate the Windows Error Reporting Service elevation‑of‑privilege vulnerability (CVE‑2026‑20817), indicating a patch is now available.

    140112948
    8.4K followersView on X
  • kokumօtօ@__kokumoto
    PoC

    Windowsエラー報告(WER)のローカル権限昇格脆弱性(CVE-2026-20817)に対応するPoC(攻撃の概念実証コード)が公表された。一般ユーザーからSYSTEM取得可能。マイクロソフトからは修正の場を借りて機能そのものを削除するWindow Updateが1月に降っており、致命傷だった模様。 https://securityonline.info/windows-error-reporting-lpe-cve-2026-20817-public-poc-exploit/

    Post summary

    A proof‑of‑concept for CVE‑2026‑20817, enabling users to elevate to SYSTEM via Windows Error Reporting, has been publicly released, and Microsoft responded in January with a patch that removes the vulnerable functionality.

    021871.3K
    7.3K followersView on X
  • Milos Constantin ♏(@Tinolle hachyderm.io )@Tinolle
    PoC

    Windows Error Reporting ALPC Elevation of Privilege (CVE-2026-20817) - Proof-of-Concept exploit demonstrating local privilege escalation via WER service. https://github.com/oxfemale/CVE-2026-20817?tab=readme-ov-file

    Post summary

    A proof‑of‑concept exploit for CVE-2026-20817 demonstrates local privilege escalation through the Windows Error Reporting service, with the exploit code hosted on GitHub.

    02031162
    3.2K followersView on X
  • Misbar | مسبار@MisbarSec
    Disclosure

    📌 استغلال ثغرة جديدة في Windows Error Reporting. تم الكشف عن ثغرة تصعيد امتيازات محلية جديدة في خدمة Windows Error Reporting (WER)، تحمل الرمز CVE-2026-20817. تستغل هذه الثغرة لتمكين المهاجمين من الحصول على صلاحية SYSTEM. يُعد هذا الوصول تهديدًا أمنيًا خطيرًا، حيث يتيح للمهاجمين التحكم الكامل بالأنظمة المتأثرة. يُنصح بتطبيق التحديثات الأمنية فور توفرها للتخفيف من هذا الخطر المحتمل وحماية الأنظمة. 🔗 للمزيد: https://cybersecuritynews.com/new-windows-error-reporting-vulnerability/

    Post summary

    A new local privilege escalation vulnerability (CVE‑2026‑20817) in Windows Error Reporting has been disclosed, with a recommendation to apply security updates promptly to mitigate the threat.

    01030519
    96 followersView on X
  • Dr.Mashari@GMashari
    Disclosure

    📌 استغلال ثغرة جديدة في Windows Error Reporting لتصعيد الامتيازات والحصول على وصول SYSTEM 🛡️ الفئة: ثغرة 📝 الملخص: تم الكشف عن ثغرة تصعيد امتيازات محلية جديدة وحاسمة في خدمة Windows Error Reporting (WER)، تحمل المعرف CVE-2026-20817. تستغل هذه الثغرة لتمكين المهاجمين من الحصول بسهولة على وصول SYSTEM الكامل إلى الأنظمة المستهدفة. يُعد هذا الوصول تهديدًا أمنيًا خطيرًا، حيث يتيح للمهاجمين التحكم الكامل بالأنظمة المتأثرة. يُنصح بتطبيق التحديثات الأمنية فور توفرها للتخفيف من هذا الخطر المحتمل وحماية الأنظمة. 🗓️ تاريخ النشر: 27/03/2026 🔗 للمزيد: https://cybersecuritynews.com/new-windows-error-reporting-vulnerability/

    Post summary

    The article announces the discovery of a critical local privilege escalation CVE-2026-20817 in Windows Error Reporting and urges users to apply the security update.

    01030130
    8.9K followersView on X
  • Dr.Mashari@GMashari
    PoC

    📌 إطلاق أداة اختراق (PoC) علنية لثغرة تصعيد امتيازات في خدمة Windows Error Reporting (CVE-2026-20817) 🛡️ الفئة: ثغرة 📝 الملخص: نشر باحث أمني أداة اختراق (PoC) وظيفية وتحليلاً معمقًا لثغرة أمنية حرجة في خدمة Windows Error Reporting (WER)، تحمل المعرف CVE-2026-20817. تستغل هذه الثغرة تصعيد الامتيازات المحلية (LPE) على أنظمة Windows، مما يمكن المهاجمين من تنفيذ تعليمات برمجية بصلاحيات أعلى. يُشكل توفر أداة الاختراق علنًا خطرًا متزايدًا لاستهداف الأنظمة غير المحدّثة، حيث يتيح استغلالاً واسع النطاق للثغرة. يُنصح بضرورة مراقبة التحديثات الأمنية من Microsoft وتطبيقها فور توفرها لتقليل المخاطر المحتملة. 🗓️ تاريخ النشر: 27/03/2026 🔗 للمزيد: https://securityonline.info/windows-error-reporting-lpe-cve-2026-20817-public-poc-exploit/

    Post summary

    A functional PoC and exploit tool for CVE‑2026‑20817, which enables local privilege escalation via Windows Error Reporting, has been publicly released, underscoring the urgency of applying Microsoft updates.

    01020119
    8.9K followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    🚨 𝐂𝐕𝐄-𝟐𝟎𝟐𝟔-𝟐𝟎𝟖𝟏𝟕 - 𝐖𝐢𝐧𝐝𝐨𝐰𝐬 𝐄𝐫𝐫𝐨𝐫 𝐑𝐞𝐩𝐨𝐫𝐭𝐢𝐧𝐠 𝐒𝐞𝐫𝐯𝐢𝐜𝐞 𝐄𝐨𝐏 • CVE-2026-20817 is a local privilege escalation vulnerability in the Windows Error Reporting service. • A low-privilege user could execute `WerFault.exe` as SYSTEM with user-controlled command line options. • The vulnerability was fixed by entirely removing the `SvcElevatedLaunch` feature from the service. The CVE-2026-20817 vulnerability allowed local privilege escalation in the Windows Error Reporting service by enabling execution of `WerFault.exe` with SYSTEM privileges through controlled command-line arguments.

    Post summary

    The post announces CVE‑2026‑20817, a local privilege escalation flaw in Windows Error Reporting that allows a low‑privilege user to run WerFault.exe as SYSTEM via crafted command‑line arguments, and notes that the issue was fixed by removing the SvcElevatedLaunch feature.

    1001074
    96 followersView on X
  • iototsecnews@iototsecnews
    PoC

    Windows WER サービスの脆弱性 CVE-2026-20817:ALPC 権限昇格の PoC が公開 https://iototsecnews.jp/2026/03/02/poc-exploit-released-for-windows-error-reporting-alpc-privilege-escalation/ 今回の脆弱性 CVE-2026-20817 は、Windows のエラー報告機能である WER サービスの仕組みが抱える問題です。具体的に言うと、ALPC (Advanced Local Procedure Call) プロトコル内の SvcElevatedLaunch というメソッドで、呼び出し元の権限確認が不十分であることに原因があります。このため、権限のないユーザーであっても、悪意のコマンドライン引数を送り込み、SYSTEM 権限で “WerFault.exe” を起動できてしまいます。高い権限を要求するサービスが、外部からの入力を安易に信用して処理を実行してしまうという、システム間の連携における境界線の管理の難しさを示しています。修正には、セキュリティ更新プログラムの適用が不可欠です。 #CVE202620817 #Microsoft #PoC #Vulnerability

    Post summary

    A proof‑of‑concept for CVE‑2026‑20817 has been released, exposing a privilege‑escalation flaw in Windows WER’s ALPC protocol; a security update is required, and no active exploitation has been reported.

    01001214
    484 followersView on X
  • iototsecnews@iototsecnews
    PoC

    Windows Error Reporting Service の脆弱性 CVE-2026-20817:SYSTEM レベル権限昇格の恐れ https://iototsecnews.jp/2026/02/10/windows-error-reporting-service-vulnerability-let-attackers-elevate-privileges-poc-released/ Windows の標準機能である Windows Error Reporting Service の脆弱性 CVE-2026-20817 について、その影響を明らかにする記事です。この問題の原因は、エラー報告を行うサービス (wersvc.dll) が、外部からのリクエストに対して権限の検証を適切に行っていなかったことにあります。本来であれば、SYSTEM 権限でのプロセス実行は厳格に制限されるべきですが、このサービスは一般ユーザーから受け入れたリクエストを、サニタイズせずに実行してしまいました。 脆弱性の観点では、CVE-2026-20817として特定されており、Windows OSの根幹に関わる特権トークンの扱い (CWE-280) に不備と判定されています。この隙を突く攻撃者は、デバッグ権限 (SeDebugPrivilege) などの権限を持ったプログラムを起動できるため、最終的にはシステム全体の完全な乗っ取りが可能になります。ご利用のチームは、ご注意ください。 #CVE202620817 #Microsoft #PoC #Vulnerability #WindowsErrorReportingService

    Post summary

    The post announces a CVE‑2026‑20817 vulnerability in Windows Error Reporting Service, explains how it allows SYSTEM‑level privilege escalation, and indicates a PoC has been released.

    01001203
    484 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Windows Error Reporting の脆弱性 CVE-2026-20817:SvcElevatedLaunch の削除による対応 https://iototsecnews.jp/2026/03/27/new-windows-error-reporting-vulnerability-lets-attackers-escalate-to-gain-system-access/ Windows Error Reporting (WER) サービスに発見された、深刻なローカル権限昇格の脆弱性 CVE-2026-20817 について解説する記事です。この問題の原因は、Windows のエラー報告を担う主要ライブラリ WerSvc.dll において、低権限のユーザーからのリクエストを処理する際の、権限チェックやデータの検証が不十分だったことにあります。 この脆弱性の構造的な危険性を重く見た Microsoft は、単なるパッチ適用に代えて、脆弱性の温床となっていた SvcElevatedLaunch 機能の完全な削除という異例の強硬手段を取りました。最新のバイナリでは、攻撃の対象となる関数が常にエラーを返すように書き換えられており、機能自体が恒久的に無効化されています。 #CVE202620817 #Microsoft #Vulnerability #WindowsErrorReporting

    Post summary

    The article explains CVE-2026-20817, a local privilege escalation flaw in Windows Error Reporting, and notes that Microsoft mitigated it by removing the SvcElevatedLaunch function. No PoC, exploit code, or active exploitation details are referenced.

    01000140
    481 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    Windowsのエラー報告サービスに深刻な欠陥、低権限ユーザーが SYSTEM 権限を奪取できる脆弱性(CVE-2026-20817) https://rocket-boys.co.jp/security-measures-lab/windows-error-reporting-privesc-cve-2026-20817/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The post announces CVE‑2026‑20817, a privilege‑escalation flaw in Windows Error Reporting that lets low‑privilege users acquire SYSTEM rights.

    00010184
    363 followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    PoC

    Proof-of-Concept Released: Public Exploit Details for Windows Error Reporting LPE (CVE-2026-20817) https://securityonline.info/windows-error-reporting-lpe-cve-2026-20817-public-poc-exploit/

    Post summary

    A public proof‑of‑concept and exploit details for the Windows Error Reporting local privilege escalation vulnerability (CVE-2026-20817) have been released.

    00001124
    237 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_11_24h2---
OSmicrosoftwindows_11_25h2---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more