CVE-2026-24294PoC(microsoft / windows_10_1607)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

4.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 19 mentions across 12 observed days
  • Momentum state: rising

What's happening

  • Exploit tool or code specified in 8 signals
  • PoC mentioned or linked in 9 signals
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 18 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 4 mentions (2026-07-19); latest day: 1
  • 19 total mentions across 12 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline19 mentions / 12d
01234Mentions · 2026-03-11: 2Mentions · 2026-03-15: 1Mentions · 2026-03-17: 2Mentions · 2026-03-25: 1Mentions · 2026-03-27: 1Mentions · 2026-06-29: 1Mentions · 2026-06-30: 2Mentions · 2026-07-01: 2Mentions · 2026-07-02: 1Mentions · 2026-07-19: 4Mentions · 2026-08-09: 1Mentions · 2026-09-24: 1PoC Mentioned / Linked · 2026-06-29: 1PoC Mentioned / Linked · 2026-06-30: 2PoC Mentioned / Linked · 2026-07-02: 1PoC Mentioned / Linked · 2026-07-19: 4PoC Mentioned / Linked · 2026-08-09: 1Exploit Tool / Code · 2026-06-29: 1Exploit Tool / Code · 2026-06-30: 2Exploit Tool / Code · 2026-07-02: 1Exploit Tool / Code · 2026-07-19: 2Exploit Tool / Code · 2026-08-09: 1Exploit Tool / Code · 2026-09-24: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-06-29: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-01: 1Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-19: 2Patch / Workaround · 2026-09-24: 1Technical Details · 2026-03-11: 2Technical Details · 2026-03-15: 1Technical Details · 2026-03-17: 2Technical Details · 2026-03-25: 1Technical Details · 2026-03-27: 1Technical Details · 2026-06-29: 1Technical Details · 2026-06-30: 2Technical Details · 2026-07-01: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-19: 4Technical Details · 2026-08-09: 1Technical Details · 2026-09-24: 103-1103-1503-1703-2503-2706-2906-3007-0107-0207-1908-0909-24
Signal classification5 categories
PoC
736.8%
Disclosure
631.6%
Patch
421.1%
General
15.3%
Exploit
15.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-112
Disclosure1Patch1
2026-03-151
Patch1
2026-03-172
Disclosure2
2026-03-251
General1
2026-03-271
Disclosure1
2026-06-291
PoC1
2026-06-302
PoC2
2026-07-012
Disclosure1Patch1
2026-07-021
Patch1
2026-07-194
Disclosure1PoC3
2026-08-091
PoC1
2026-09-241
Exploit1
Full discourse19 posts
  • Daily CyberSecurity@the_yellow_fall
    PoC

    Researcher publicly disclosed an NTLM reflection bypass, CVE-2026-24294, with PoC exploit code. It gives SYSTEM on Windows Server 2025. Patch now. #NTLM #NTLMReflection #CVE202624294 #Windows #PrivEsc #Cybersecurity #Infosec https://securityonline.info/ntlm-reflection-cve-2026-24294/ https://t.co/GOALlYOzyg

    Post summary

    The tweet announces the public disclosure of CVE-2026-24294, an NTLM reflection bypass that enables SYSTEM privilege escalation on Windows Server 2025, and notes that PoC exploit code and a patch are available.

    761325416727.5K
    12.9K followersView on X
  • Blackstorm Security@blackstormsecbr
    PoC

    CVE-2026-24294 - Local NTLM Reflection LPE via SMB Arbitrary Port: https://github.com/0xNDI/CVE-2026-24294 #smb #vulnerability #infomationsecurity #infosec #cybersecurity #exploit #exploitation https://t.co/LPPBCoXNXu

    Post summary

    The tweet shares a proof‑of‑concept code repository for CVE‑2026‑24294, a local NTLM reflection privilege‑on‑effect vulnerability via SMB, without indicating active exploitation or a fix.

    375025114312.2K
    2.4K followersView on X
  • Ryx@PadhiyarRushi
    Exploit

    NTLM reflection is not dead!! Unicode homoglyph + Kerberos coerce → SYSTEM. After CVE-2025-33073, the SMB-client mitigation still missed arbitrary-port SMB reuse and homoglyph names (SⓇhttp://V1.AD.LOCAL). Coerce LSASS onto a multiplexed TCP session, relay with ntlmrelayx / krbrelayx, land nt authority\system. Default-on for Server 2025. Win11 24H2 signing blocks the SMB half. Follow-on: CVE-2026-24294 https://www.synacktiv.com/en/publications/bypassing-windows-authentication-reflection-mitigations-for-system-shells-part #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #ActiveDirectory #NTLM #RedTeam #Windows

    Post summary

    The tweet details a bypass for CVE-2025-33073 using Unicode homoglyphs and Kerberos coercion to achieve SYSTEM via NTLM relay, explicitly naming the exploit tools ntlmrelayx and krbrelayx, while noting mitigations in Windows 11 24H2 and Server 2025.

    10053502
    954 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Patch

    🔴 CVE-2026-24294 | Local NTLM Reflection LPE via SMB Arbitrary Port 10 Mart 2026'da Microsoft tarafından yamalanan bu açık, Windows 11 24H2 / Windows Server 2025'teki SMB Arbitrary Port ve SMB Session Multiplexing davranışını kullanarak NTLM Reflection saldırısını mümkün kılıyor. PoC 3 ay önce yayınlandı ve varsayılan yapılandırmada Windows Server 2025'i hedefliyor, ancak CVE, Windows 11 24H2 için de Microsoft tarafından Mart 2026 güncellemeleriyle giderildi. Yani bu işletim sistemlerine sahipseniz ve mart 2026 güncellemesini aldırmadıysanız, aldırın. https://github.com/0xNDI/CVE-2026-24294

    Post summary

    Microsoft patched CVE‑2026‑24294 in the March 2026 update after a PoC was publicly released; users running Windows 11 24H2 or Windows Server 2025 should install the update if not already.

    00011216
    1.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Source: X search for PoC exploit 2026 Posted: 2026-06-29T08:57:12.000Z Likes: 152 0day Intel: Researcher publicly disclosed an NTLM reflection bypass, CVE-2026-24294, with Po

    Post summary

    A researcher publicly disclosed CVE‑2026‑24294, an NTLM reflection bypass, along with a proof‑of‑concept, but no active exploitation or patch information is reported.

    1000085
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    Full Tweet Researcher publicly disclosed an NTLM reflection bypass, CVE-2026-24294, with PoC exploit code. It gives SYSTEM on Windows Server 2025. Patch now.

    Post summary

    A researcher disclosed CVE-2026-24294, providing a PoC exploit that elevates privileges to SYSTEM on Windows Server 2025, and a patch is now available.

    1000083
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    0day Intel: Researcher publicly disclosed an NTLM reflection bypass, CVE-2026-24294, with Po

    Post summary

    A researcher has publicly disclosed a new NTLM reflection bypass (CVE-2026-24294) and shared a PoC, but no exploit tools, active exploitation, or patch details are noted.

    1000053
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    CVE-2026-24294: Researcher publicly disclosed an NTLM reflection bypass, CVE-2026-24294, with PoC exploit code. It gives SYSTEM on Windows Server 2025. Patch now. #NTLM #NTLMReflection #CVE202624294 #Windows #PrivEsc #Cybersecurity #Infosec

    Post summary

    A researcher publicly disclosed CVE‑2026‑24294, a NTLM reflection bypass that can give SYSTEM privileges on Windows Server 2025, and shared PoC exploit code. A patch is now available to mitigate the vulnerability.

    1000095
    326 followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    Microsoft وصفت CVE-2026-24294 كالتالي: ـWindows SMB Server Elevation of Privilege السبب: Improper Authentication الأثر: Elevation of Privilege محلي والنجاح قد يمنح SYSTEM privileges

    Post summary

    Microsoft has officially disclosed technical details of CVE-2026-24294, describing it as a local elevation of privilege flaw in Windows SMB Server caused by improper authentication, which could grant SYSTEM privileges.

    10000303
    49.2K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    هذه النتيجة أثبتت أن تصحيح CVE-2025-33073 عالج المسار الأول، لكنه لم يعالج أصل المشكلة بالكامل. Microsoft تعاملت مع هذا الـ bypass كثغرة مستقلة جديدة: CVE-2026-24294

    Post summary

    Microsoft’s fix for CVE‑2025‑33073 only partially resolved the issue, prompting a new bypass vulnerability designated CVE‑2026‑24294.

    1000085
    49.2K followersView on X
  • キタきつね@foxbook
    PoC

    NTLMリフレクションバイパスCVE-2026-24294の脆弱性を悪用するPoCエクスプロイトが公開される NTLM Reflection Bypass CVE-2026-24294 Gets Public PoC Exploit #DailyCyberSecurity (Jun 29) https://securityonline.info/ntlm-reflection-cve-2026-24294/

    Post summary

    A public PoC exploit for the NTLM Reflection Bypass CVE‑2026‑24294 has been released, with no evidence of active exploitation, patches, or false‑positive reports.

    00010340
    4.9K followersView on X
  • Vicarius@vicariusltd
    General

    Nahuel and his team investigate deeply integrated vulnerabilities and reduce the attack surface with disabling, blocking, and other fun configurations. CVEs covered: CVE-2025-25017 Cross-Site Scripting in Kibana Vega Visualization Engine CVE-2026-0386 Remote Code Execution in Windows Deployment Services CVE-2026-24294 SMB Server Improper Authentication https://www.linkedin.com/pulse/issue-14-risk-ripples-outward-vicarius-g3qzc/

    Post summary

    The post merely enumerates several CVEs with short vulnerability type tags and does not provide PoC, exploit, active exploitation, or patch information.

    00010209
    2.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24294 Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-24294

    Post summary

    The text announces CVE-2026-24294, describing an improper authentication flaw in Windows SMB Server that permits local privilege escalation, without indicating PoC, exploit code, active exploitation, or a patch.

    00010182
    56.7K followersView on X
  • ✮ Cymon Skinner ✮@CymonSkinner
    Patch

    Microsoft's March 2026 Patch Tuesday addresses 84 vulnerabilities, including two public zero-days that demand immediate attention from CISOs. Prioritise patching critical RCE flaws in Windows RRAS (CVE-2026-25172) and SharePoint (CVE-2026-26106), as these align with common attack paths in real-world breaches. With over 40 elevation of privilege issues, focus your Sentinel triage on exploitation-more-likely CVEs like CVE-2026-24294 in SMB Server. Swift action bridges skills gaps in vulnerability management. #PatchTuesday #Cybersecurity

    Post summary

    Microsoft’s March 2026 Patch Tuesday announces 84 vulnerabilities, urging immediate patching of critical RCE flaws in RRAS, SharePoint, and escalation of privilege issues like CVE-2026-24294.

    0001063
    711 followersView on X
  • kawn@kawn2020
    Disclosure

    #windowsupdate #microsoft (つづき) ・CVE-2026-24291 7.8 Windows ユーザー補助インフラストラクチャ (ATBroker.exe) ・CVE-2026-24294 7.8 Windows SMB サーバー ・CVE-2026-25187 7.8 Winlogon ・CVE-2026-26132 7.8 Windows カーネル

    Post summary

    The tweet announces several Windows CVEs with CVSS 7.8 ratings and specifies the affected components, but provides no PoC, exploit, or mitigation details.

    1000079
    89 followersView on X
  • ChrisUK2026@chris_uk2026
    PoC

    Researcher publicly disclosed an NTLM reflection bypass, CVE-2026-24294, with PoC exploit code. It gives SYSTEM on Windows Server 2025. Patch now. #NTLM #NTLMReflection #CVE202624294 #Windows #PrivEsc #Cybersecurity #Infosec http://securityonline.info/ntlm-reflectio…

    Post summary

    Researchers disclosed CVE-2026-24294 with a PoC exploit that grants SYSTEM on Windows Server 2025 and a patch has already been issued.

    00000102
    25 followersView on X
  • White Rabbitx@TheRabbitPy
    Disclosure

    📁 SMB auth bypass (CVE-2026-24294) Core SMB skips auth checks (CVSS 7.8). Network-adjacent pwns shares. Hunt anomalous SMB access in logs NOW. https://krebsonsecurity.com/2026/03/microsoft-patch-tuesday-march-2026-edition/ #SMB #CVE

    Post summary

    The post announces CVE‑2026‑24294, an SMB authentication bypass with a CVSS score of 7.8, offering technical details but no PoC or patch information.

    0000029
    492 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-24294 Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-24294 ----- Traducción: CVE-2026-24294 Autenticación inadecuada en Windows SMB Server permite a un ataca… http://infoflow.cloud`

    Post summary

    The tweet announces the newly disclosed Windows SMB Server privilege‑escalation vulnerability (CVE‑2026‑24294) and links to its CVE record, but it does not provide a PoC, exploit code, evidence of active exploitation, patch, or de‑mistification.

    0000043
    59 followersView on X
  • CybrPulse@CybrPulse
    Patch

    March Patch Tuesday: 77 CVEs, no zero-days. Two Office flaws to prioritize: CVE-2026-26113 and CVE-2026-26110 both trigger RCE just by previewing a message. No clicks needed. Also CVE-2026-24294 (SMB auth bypass). Patch now. https://krebsonsecurity.com/2026/03/microsoft-patch-tuesday-march-2026-edition/ #infosec

    Post summary

    The tweet announces Microsoft’s March Patch Tuesday, listing 77 CVEs with three critical flaws and urging immediate patching.

    0000053
    19 followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025--x64

Explore more