Vulnerability in Windows Node Exec-Approval Policy Exposes Systems to EoP
Article Content
- •A critical vulnerability allows arbitrary code execution via exec-approval policy misconfiguration.
- •Exploitation can occur through whitelisting of LOLBins like mshta and regsvr32.
- •No patches are available, and the vulnerability is actively exploited.
A vulnerability in the Windows node's exec-approval policy allows remote callers to weaken execution restrictions, leading to potential arbitrary code execution. The flaw arises from the improper validation of Allow rules, which can be exploited to whitelist dangerous commands, including living-off-the-land binaries (LOLBins) like mshta and regsvr32. This vulnerability affects systems using the exec-approval policy and can be exploited without proper authorization checks. The issue has been classified under CWE-863 (Incorrect Authorization) and CWE-184 (Incomplete List of Disallowed Inputs). Currently, there are no known patches or fixes released, and the vulnerability is actively being. Security professionals are urged to review their exec-approval policies and limit access to the system.execApprovals.set function. The threat model indicates that a compromised token can lead to a two-step escalation of privileges. The situation remains as the vulnerability is and poses a significant risk to affected systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What systems are affected?
Is there a patch available?
What immediate actions should be taken?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…