Skip to content
RegPwn: Critical Windows Registry Flaw Grants SYSTEM Access

RegPwn: Critical Windows Registry Flaw Grants SYSTEM Access

First seen 18 Mar 2026, 08:42 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 19, 2026 at 08:12 UTC
  • •RegPwn (CVE-2026-24291) allows low-privileged users to gain SYSTEM access.
  • •The vulnerability was discovered by MDSec and has been known since January 2025.
  • •Microsoft released a patch for RegPwn on March 10, 2026.

Researchers at MDSec have disclosed a critical Elevation of Privilege vulnerability in Microsoft Windows, identified as 'RegPwn' and tracked as CVE-2026-24291. This vulnerability allows low-privileged users to gain full SYSTEM access by exploiting the handling of registry configurations for Windows Accessibility features. The flaw was discovered during internal engagements by MDSec's red team, who have been aware of it since January 2025. Microsoft addressed the issue in a recent Patch Tuesday update on March 10, 2026. The flaw affects various Windows systems utilizing Accessibility features like the On-Screen Keyboard and Narrator. Security professionals are urged to apply the patch immediately to mitigate potential exploitation. The vulnerability has been classified as high severity due to its potential impact on system security.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 204d ago How this analysis works

Timeline

2025-01-05
MDSec red team discovers RegPwn vulnerability
2026-03-10
CVE-2026-24291 published and patched by Microsoft
2026-03-18
RegPwn vulnerability disclosed in cybersecurity articles

More articles in this cluster (2)

Following this threat?

Track MDSec and CVE-2026-24291 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed