CVE-2026-24291Disclosure(microsoft / windows_10_1607)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.

4.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-732

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 27 mentions across 11 observed days
  • Momentum state: declining

What's happening

  • Exploit tool or code specified in 7 signals
  • PoC mentioned or linked in 14 signals
  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 23 signals
  • Disclosure: 10 classified signals
  • General: 3 classified signals
  • Peaked 7d ago at 6 mentions (2026-03-18); latest day: 1
  • 27 total mentions across 11 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline27 mentions / 11d
02356Mentions · 2026-03-11: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 5Mentions · 2026-03-18: 6Mentions · 2026-03-19: 2Mentions · 2026-03-20: 2Mentions · 2026-03-23: 5Mentions · 2026-03-25: 2Mentions · 2026-03-26: 1Mentions · 2026-03-29: 1Mentions · 2026-05-19: 1PoC Mentioned / Linked · 2026-03-16: 1PoC Mentioned / Linked · 2026-03-17: 2PoC Mentioned / Linked · 2026-03-18: 4PoC Mentioned / Linked · 2026-03-19: 1PoC Mentioned / Linked · 2026-03-20: 1PoC Mentioned / Linked · 2026-03-23: 2PoC Mentioned / Linked · 2026-03-25: 2PoC Mentioned / Linked · 2026-03-26: 1Exploit Tool / Code · 2026-03-16: 1Exploit Tool / Code · 2026-03-18: 3Exploit Tool / Code · 2026-03-20: 1Exploit Tool / Code · 2026-03-25: 1Exploit Tool / Code · 2026-03-26: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-03-18: 2Patch / Workaround · 2026-03-19: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-23: 2Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-29: 1Patch / Workaround · 2026-05-19: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 4Technical Details · 2026-03-18: 6Technical Details · 2026-03-19: 2Technical Details · 2026-03-20: 2Technical Details · 2026-03-23: 3Technical Details · 2026-03-25: 2Technical Details · 2026-03-26: 1Technical Details · 2026-03-29: 103-1103-1603-1703-1803-1903-2003-2303-2503-2603-2905-19
Signal classification5 categories
Disclosure
1037.0%
PoC
933.3%
General
311.1%
Patch
311.1%
Exploit
27.4%
Referenced assets19 URLs
Classification over time
DateTotalLabels
2026-03-111
Disclosure1
2026-03-161
PoC1
2026-03-175
Disclosure3General1PoC1
2026-03-186
Disclosure2PoC4
2026-03-192
Disclosure1PoC1
2026-03-202
Patch1PoC1
2026-03-235
Disclosure3General2
2026-03-252
Exploit1PoC1
2026-03-261
Exploit1
2026-03-291
Patch1
2026-05-191
Patch1
Full discourse20 posts
  • Cyber Security News@The_Cyber_News
    Disclosure

    ⚠️ ‘RegPwn’ Windows Registry Vulnerability Enables Full System Access to Attackers Source: https://cybersecuritynews.com/regpwn-windows-registry-vulnerability/ A high-severity Windows vulnerability dubbed “RegPwn” (CVE-2026-24291) is an elevation-of-privilege flaw that allows low-privileged users to gain full SYSTEM access. The attack targets the way Windows manages its built-in accessibility features, such as the On-Screen Keyboard and Narrator. Windows Accessibility features are designed to help users navigate the operating system, operating primarily in the user’s context but with high-integrity access. When a user launches a tool like the On-Screen Keyboard, Windows creates a specific registry key to store its configuration. #cybersecuritynews

    Post summary

    This article discloses a new high‑severity Windows elevation‑of‑privilege flaw (CVE‑2026‑24291) that exploits accessibility features such as the On‑Screen Keyboard, offering no PoC, exploit code, or patch details.

    38562228111.3K
    51.4K followersView on X
  • Clandestine@akaclandestine
    Exploit

    CVE-2026-24291: Windows LPE (RegPwn) Exploit: https://github.com/mdsecactivebreach/RegPwn Blog: https://www.mdsec.co.uk/2026/03/rip-regpwn/ BOF: https://github.com/Flangvik/RegPwnBOF Tested versions: Windows 11 25h2 Windows 11 24h2 Windows 10 21h2 Windows Servers 2016/2019/2022 Patched: Mar 10, 2026 #lpe #pentest #redteam #ad #cve

    Post summary

    CVE-2026-24291 is a disclosed Windows LPE flaw that now has publicly available exploit code, a BOF variant, and a vendor patch released on March 10, 2026.

    1500158957.6K
    57.0K followersView on X
  • Hermes Tool@Hermes_tooll
    Exploit

    CVE-2026-24291: Windows LPE (RegPwn) Exploit: https://github.com/mdsecactivebreach/RegPwn Blog: https://mdsec.co.uk/2026/03/rip-regpwn/ BOF: https://github.com/Flangvik/RegPwnBOF Tested versions: Windows 11 25h2 Windows 11 24h2 Windows 10 21h2 Windows Servers 2016/2019/2022 Patched: Mar 10, 2026 #lpe #pentest #redteam #ad #cve

    Post summary

    The message announces a functional RegPwn exploit for CVE-2026-24291, links code repositories, references a blog, lists impacted Windows versions, and notes a formal patch date.

    0280103594.5K
    3.4K followersView on X
  • Melvin langvik@Flangvik
    PoC

    This week’s video covers CVE-2026-24291, a Windows LPE nicknamed RegPwn by the team over at @MDSecLabs. As a part-time sloperator (Google it), I whipped up a quick RegPwn BOF, and in the video I demo it with Mythic and Apollo. Link below. https://t.co/nXCiFYoMi9

    Post summary

    The video showcases a quick RegPwn proof‑of‑concept for CVE-2026-24291, a Windows local privilege escalation vulnerability, demonstrated using Mythic and Apollo.

    317092345.9K
    11.4K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    Discover RegPwn (CVE-2026-24291), a critical Windows flaw in the On-Screen Keyboard that allowed attackers to seize SYSTEM control. Patch released March 2026. https://meterpreter.org/beyond-the-secure-desktop-how-regpwn-turned-windows-accessibility-into-a-system-level-backdoor/ https://t.co/THAZ0OK02m

    Post summary

    The post announces the discovery of CVE-2026-24291, a critical flaw in Windows On‑Screen Keyboard, and notes that a patch was released in March 2026.

    19026101.6K
    10.7K followersView on X
  • dbugs@ptdbugs
    Disclosure

    RegPwn Vulnerability in Windows Accessibility MDSec’s research describes a privilege escalation vulnerability "RegPwn" (CVE-2026-24291 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-24291)), affecting Windows 10/11 and Windows Server 2012–2025. The flaw originates from the way Accessibility mechanisms handle parameters — insecure registry permissions allowed a local user to overwrite values and execute arbitrary code with SYSTEM privileges. The exploit was previously kept private, having been utilized in Red Team engagements since January 2025. Microsoft addressed the vulnerability in the March 2026 Patch Tuesday update. While exploitation requires local access, it results in a full system compromise. 📎 Article: https://www.mdsec.co.uk/2026/03/rip-regpwn/ #dbugs_attacks

    Post summary

    Details a Windows privilege‑escalation flaw in accessibility parameters, includes affected OS versions and a March 2026 patch, but no PoC or active exploitation evidence is presented.

    05025132.1K
    733 followersView on X
  • Nicolas Krassas@Dinosn
    General

    RegPwn (CVE-2026-24291): Windows Registry Vulnerability Explained https://blog.securelayer7.net/cve-2026-24291-regpwn-windows-privilege-escalation/

    Post summary

    The content simply references CVE‑2026‑24291 and links to a blog post that presumably explains it, but offers no PoC, exploit details, or mitigation information in the excerpt.

    0802181.9K
    153.5K followersView on X
  • 0patch@0patch
    Patch

    Micropatches released for Windows Accessibility Infrastructure Elevation of Privilege Vulnerability (CVE-2026-24291, CVE-2026-25186, CVE-2026-25187) https://blog.0patch.com/2026/05/micropatches-released-for-windows.html https://t.co/1be3lEyUD2

    Post summary

    Micro patches have been released for three Windows Accessibility Infrastructure elevation-of-privilege vulnerabilities (CVE-2026-24291, CVE-2026-25186, CVE-2026-25187), as announced on the 0patch blog.

    140102985
    8.4K followersView on X
  • Gray Hats@the_yellow_fall
    PoC

    Exploit code and details for RegPwn (CVE-2026-24291) are publicly disclosed. The Windows local privilege escalation flaw grants attackers SYSTEM access. #RegPwn #CVE #WindowsSecurity #PoCExploit #CyberSecurity #InfoSec #PrivilegeEscalation #Vulnerability https://securityonline.info/poc-exploit-publicly-disclosed-regpwn-flaw-windows-accessibility-cve-2026-24291/ https://t.co/XjXbqtC35i

    Post summary

    The post announces that exploit code and details for CVE‑2026‑24291 have been publicly released, confirming the existence of a PoC but providing no evidence of active exploitation or patches.

    020132689
    10.7K followersView on X
  • Günter Born@etguenni
    Patch

    #RegPwn - eine Schwachstelle in Windows, die Nutzern eine Rechteausweitung per Registry ermöglicht, wurde still im März 2026 per Update gepatcht. https://borncity.com/blog/2026/03/20/windows-registry-schwachstelle-regpwn-cve-2026-24291-am-10-maerz-2026-gefixt/

    Post summary

    The article reports that CVE‑2026‑24291, a Windows registry‑based privilege escalation flaw, was quietly fixed in March 2026 with an update.

    00040298
    2.6K followersView on X
  • Misbar | مسبار@MisbarSec
    PoC

    📌 الكشف العلني عن استغلال PoC: ثغرة RegPwn تمنح وصول SYSTEM عبر Windows Accessibility اكتُشفت ثغرة أمنية جديدة، تُعرف باسم "RegPwn" وتُصنّف تحت CVE-2026-24291، ضمن بنية Windows Accessibility التحتية. تسمح هذه الثغرة بتصعيد الامتيازات محلياً، مما يمنح المهاجمين وصولاً بمستوى SYSTEM على الأنظمة المستهدفة. تم الكشف علناً عن دليل استغلال (PoC) لهذه الثغرة، مما يزيد من خطورة التهديد ويحتمل أن يؤدي إلى استغلال واسع النطاق. يُنصح المؤسسات والفرادى بتتبع تحديثات الأمان الصادرة عن Microsoft ومعالجتها فور توفرها لتخفيف المخاطر. 🔗 للمزيد: https://securityonline.info/poc-exploit-publicly-disclosed-regpwn-flaw-windows-accessibility-cve-2026-24291/

    Post summary

    تم الكشف علنًا عن ثغرة RegPwn (CVE‑2026‑24291) مع إصدار PoC، تسمح بترقية الامتيازات محليًا إلى SYSTEM، وينصح المؤسسات بتطبيق التحديثات المتاحة من Microsoft.

    00040513
    71 followersView on X
  • VulnTracker@vuln_tracker
    PoC

    @Flangvik @MDSecLabs Love seeing BOF development for fresh Windows LPE vulns! RegPwn (CVE-2026-24291) getting the C2 framework integration treatment is exactly what red teams need. https://vulntracker.io/cves/CVE-2026-24291

    Post summary

    The post celebrates the development and C2 integration of RegPwn’s PoC for CVE-2026-24291, a Windows LPE flaw, but offers no exploit code or evidence of active abuse.

    00030190
    426 followersView on X
  • iototsecnews@iototsecnews
    PoC

    Windows の脆弱性 RegPwn CVE-2026-24291:システム権限の取得と PoC の公開 https://iototsecnews.jp/2026/03/18/regpwn-windows-registry-vulnerability-enables-full-system-access-to-attackers/ ”RegPwn” と呼ばれる Windows の脆弱性 CVE-2026-24291 の原因は、ユーザーが設定したデータが、SYSTEM 権限で動作する領域へコピーされる際の管理不備にあります。アクセシビリティ機能の設定を保存するレジストリ・キー に対して、一般ユーザーが書き込み権限を持っていることが問題の始まりです。その結果として、この設定をシステムがコピーする際に、oplock という仕組みで処理を一時停止させ、その隙にリンク先をすり替える攻撃が許されてしまいます。本来は分離されるべき一般ユーザーの操作と、OS の重要な処理が交差する瞬間に生まれる深刻な欠陥と言えます。ご利用のチームは、ご注意ください。 #CVE202624291 #Microsoft #PoC #RegPwn #Vulnerability

    Post summary

    The article reports the discovery of the RegPwn Windows vulnerability (CVE‑2026‑24291) and confirms that a PoC demonstrating SYSTEM‑level escalation has been released, but provides no evidence of active exploitation, patches, or detailed exploit code.

    02000142
    481 followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    RegPwnことCVE-2026-24291は、WindowsのATBroker.exeを悪用して低権限ユーザーからSYSTEM権限まで上がれるローカル権限昇格脆弱性。重要なのは、原因がWindows Accessibility Infrastructureの不適切な権限設定にあり、PoCも公開済みで実戦投入しやすい点。 影響はWindows Accessibility InfrastructureのATBroker.exeで、NVDはCVSS 7.8、高権限リソースへの誤った権限付与によるLPEと説明している。攻撃にはローカル実行権限が必要だが、成功するとSYSTEM権限取得につながる。 公開解説では、アクセシビリティ機能まわりの信頼境界とレジストリ操作を悪用して昇格する流れが示されている。Microsoftは2026年3月10日に修正を公開しており、未更新端末は優先して塞ぐべき案件。 APT: なし Malware: なし CVE: CVE-2026-24291 IoC: ATBroker.exe, Windows Accessibility Infrastructure, local privilege escalation, SYSTEM privilege, public PoC #CyberSecurity #ThreatIntel #Windows #PrivEsc #CVE202624291 https://blog.securelayer7.net/cve-2026-24291-regpwn-windows-privilege-escalation/

    Post summary

    The post discloses CVE‑2026‑24291, a local privilege escalation in Windows ATBroker.exe, provides a public PoC and acknowledges Microsoft’s March 10 fix, with no evidence of current active exploitation.

    00020341
    3.4K followersView on X
  • Autumn Good@autumn_good_35
    General

    RegPwn (CVE-2026-24291): Windows Registry Vulnerability Explained https://blog.securelayer7.net/cve-2026-24291-regpwn-windows-privilege-escalation/

    Post summary

    The blog link references CVE-2026-24291, a Windows Registry privilege‑escalation vulnerability, but provides no PoC, exploit, or detailed technical or patch information.

    00001367
    6.7K followersView on X
  • BreachBriefs@BreachBrief
    PoC

    🚨 #RegPwn | CVE-2026-24291 | Windows Privilege Escalation | March 2026 A clever Windows vulnerability discovered by MDSec red team lets any low-privileged user escalate to full SYSTEM access — silently! Here's how it works 👇 The attack targets Windows accessibility features like On-Screen Keyboard. When launched, Windows creates a writable registry key. At workstation lock, the attacker swaps this key with a symbolic link pointing to a restricted system registry location — since the copying process runs as SYSTEM, arbitrary values get written to protected areas. Result: Full SYSTEM shell — game over! ✅ Patched in March 2026 Patch Tuesday 🛡️ Apply Windows updates NOW — PoC is already public on GitHub! #Windows #PrivEsc #PatchNow #BlueTeam #RedTeam #InfoSec

    Post summary

    The post announces a Windows privilege escalation flaw (CVE‑2026‑24291) that leverages accessibility features; a PoC is publicly available on GitHub and the issue was patched in March 2026, with users urged to apply the update.

    0001037
    7 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    RegPwn (CVE-2026-24291) is a critical Windows registry flaw allowing low-privileged users to gain SYSTEM access, fixed in the March 10, 2026 Patch Tuesday update. Admins should patch now. https://threatcluster.io/cluster/regpwn-critical-windows-registry-flaw-grants-system-access-6853b49b

    Post summary

    RegPwn (CVE-2026-24291) is a critical Windows registry flaw that lets low-privileged users attain SYSTEM rights; it was fixed in the March 10, 2026 Patch Tuesday update, and admins are urged to patch.

    0001044
    104 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2010-5139 2 - CVE-2026-24291 3 - CVE-2019-17571 4 - CVE-2025-47813 5 - CVE-2026-25172 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five CVE identifiers as trending topics but offers no further details, tools, or actionable information.

    00010212
    1.7K followersView on X
  • kawn@kawn2020
    Disclosure

    #windowsupdate #microsoft (つづき) ・CVE-2026-24291 7.8 Windows ユーザー補助インフラストラクチャ (ATBroker.exe) ・CVE-2026-24294 7.8 Windows SMB サーバー ・CVE-2026-25187 7.8 Winlogon ・CVE-2026-26132 7.8 Windows カーネル

    Post summary

    The post lists several newly disclosed Windows CVEs with a severity score of 7.8 and brief component descriptions, but provides no PoC, exploit, or patch information.

    1000079
    89 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Patch

    🚨 #CVE-2026-24291 (RegPwn): Critical #Windows LPE Exploit Exposes Full System Compromise – Patch Now! + Video https://undercodetesting.com/cve-2026-24291-regpwn-critical-windows-lpe-exploit-exposes-full-system-compromise-patch-now-video/ Educational Purposes!

    Post summary

    The tweet announces the CVE‑2026‑24291 Windows local privilege escalation vulnerability, urges users to apply a patch, and links to a video, but provides no exploit code or evidence of active abuse.

    0000048
    453 followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025--x64

Explore more