Cybersecuritynews RegPwn: Critical Windows Registry Flaw Grants SYSTEM Access
Article Content
- •RegPwn (CVE-2026-24291) allows low-privileged users to gain SYSTEM access.
- •The vulnerability was discovered by MDSec and has been known since January 2025.
- •Microsoft released a patch for RegPwn on March 10, 2026.
Researchers at MDSec have disclosed a critical Elevation of Privilege vulnerability in Microsoft Windows, identified as 'RegPwn' and tracked as CVE-2026-24291. This vulnerability allows low-privileged users to gain full SYSTEM access by exploiting the handling of registry configurations for Windows Accessibility features. The flaw was discovered during internal engagements by MDSec's red team, who have been aware of it since January 2025. Microsoft addressed the issue in a recent Patch Tuesday update on March 10, 2026. The flaw affects various Windows systems utilizing Accessibility features like the On-Screen Keyboard and Narrator. Security professionals are urged to apply the patch immediately to mitigate potential exploitation. The vulnerability has been classified as high severity due to its potential impact on system security.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track MDSec and CVE-2026-24291 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Netlogon Vulnerability CVE-2026-41089 Exploited A critical vulnerability, CVE-2026-41089, was identified in Windows Netlogon, allowing unauthenticated attackers to exploit a stack buffer overflow. This vulnerability enables attackers to execute arbitrary code at the NT AUTHORITY\SYSTEM level, posing a severe risk to Active Directory environments. The exploit does…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…