CVE-2026-20817 – Windows Error Reporting Privilege Escalation Patch

CVSS 7.8 IMPORTANT

“A silent reporting feature opened the door to system-level control.”

Microsoft addressed a high-severity vulnerability in Windows Error Reporting that could allow local attackers to escalate privileges. The issue enables an attacker with limited access to gain elevated permissions, potentially leading to full system compromise. CVE-2026-20817 has a CVSS score of 7.8, which is High severity.

Proof-of-concept code is publicly available, increasing the risk of exploitation in real-world environments. This makes timely patching critical, especially for systems where local access is possible or shared environments are in use.

Key Details

Affected Product
Microsoft Windows 10 21h2
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-280
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.