CVE-2024-26169: Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability
Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.
Other sources
Windows Error Reporting Service Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20526Patch KB5035858 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.21871Patch KB5035885 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.3296Patch KB5035853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.6796Patch KB5035855 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.763Patch KB5035856 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.4170Patch KB5035845 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.3296Patch KB5035853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.4170Patch KB5035845 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.2836Patch KB5035854 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2340Fixed in 10.0.20348.2333Patch KB5035959 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.5576Patch KB5035849 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.10240.20526Patch KB5035858 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.14393.6796Patch KB5035855 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.17763.5576Patch KB5035849 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.19044.4170Patch KB5035845 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.19045.4170Patch KB5035845 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.20348.2340Patch KB5035959 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.20348.2333Patch KB5035959 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.22000.2836Patch KB5035854 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.22621.3296Patch KB5035853 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.22631.3296Patch KB5035853 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 10.0.25398.763Patch KB5035856 - Upgrade
Upgrade
Microsoft Windows Operating Systemto a version that resolves this vulnerability.Fixed in 6.3.9600.21871Patch KB5035885
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26169?
CVE-2024-26169 is rated as a high-severity vulnerability that allows local attackers to escalate privileges to SYSTEM level.
How do I fix CVE-2024-26169?
To remediate CVE-2024-26169, install the security updates provided by Microsoft corresponding to your Windows version.
Which versions of Windows are affected by CVE-2024-26169?
CVE-2024-26169 affects multiple versions of Windows, including Windows 10, Windows 11, and various Windows Server editions.
What type of vulnerability is CVE-2024-26169?
CVE-2024-26169 is classified as an elevation of privilege vulnerability within the Microsoft Windows Error Reporting Service.
Can a remote attacker exploit CVE-2024-26169?
No, CVE-2024-26169 can only be exploited by a local attacker with user permissions on the affected system.