Skip to content
Critical Windows Error Reporting Vulnerability Allows SYSTEM Access via Privilege Escalation

Critical Windows Error Reporting Vulnerability Allows SYSTEM Access via Privilege Escalation

First seen 27 Mar 2026, 07:45 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 28, 2026 at 07:45 UTC
  • •CVE-2026-20817 allows local privilege escalation to SYSTEM access.
  • •Microsoft removed the vulnerable feature entirely due to its severity.
  • •The vulnerability was first publicly disclosed on January 13, 2026.

A local privilege escalation vulnerability in the Windows Error Reporting (WER) service, tracked as CVE-2026-20817, has been identified, allowing attackers to gain full SYSTEM access. This flaw enables local users with standard rights to escalate their privileges through improper permission handling. Due to the severity of the vulnerability, Microsoft has opted to completely remove the affected feature instead of issuing a traditional patch. The vulnerability was published on January 13, 2026, and the first proof of concept (PoC) was released on February 18, 2026. This poses a significant risk to systems running affected versions of Windows. Organizations are urged to assess their systems for exposure to this vulnerability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 194d ago How this analysis works

Timeline

2026-01-13
CVE-2026-20817 published
2026-02-18
First public PoC released
2026-03-27
Microsoft removes the vulnerable feature

More articles in this cluster (2)

Following this threat?

Track CVE-2026-20817 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed