Skip to content
Vulnerability in Windows Node Exec-Approval Policy Exposes Systems to EoP

Vulnerability in Windows Node Exec-Approval Policy Exposes Systems to EoP

First seen 1 Oct 2026, 01:58 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 01:59 UTC
  • •A critical vulnerability allows arbitrary code execution via exec-approval policy misconfiguration.
  • •Exploitation can occur through whitelisting of LOLBins like mshta and regsvr32.
  • •No patches are available, and the vulnerability is actively exploited.

A vulnerability in the Windows node's exec-approval policy allows remote callers to weaken execution restrictions, leading to potential arbitrary code execution. The flaw arises from the improper validation of Allow rules, which can be exploited to whitelist dangerous commands, including living-off-the-land binaries (LOLBins) like mshta and regsvr32. This vulnerability affects systems using the exec-approval policy and can be exploited without proper authorization checks. The issue has been classified under CWE-863 (Incorrect Authorization) and CWE-184 (Incomplete List of Disallowed Inputs). Currently, there are no known patches or fixes released, and the vulnerability is actively being. Security professionals are urged to review their exec-approval policies and limit access to the system.execApprovals.set function. The threat model indicates that a compromised token can lead to a two-step escalation of privileges. The situation remains as the vulnerability is and poses a significant risk to affected systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-01
Vulnerability disclosed
The flaw in the exec-approval policy was disclosed, highlighting risks of arbitrary code execution.
github.com
2026-10-01
Second advisory published
A second advisory confirmed the vulnerability's exploitation potential through LOLBins.
github.com

More articles in this cluster (2)

Common questions

What systems are affected?
Any systems using the Windows node exec-approval policy are at risk.
Is there a patch available?
No patches or fixes have been released as of now.
What immediate actions should be taken?
Review and restrict access to the system.execApprovals.set function to prevent exploitation.