PT-2024-2247 · Microsoft · Windows Error Reporting Service+1

Naceri

·

Published

2024-03-12

·

Updated

2025-09-17

·

CVE-2024-26169

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows Error Reporting Service versions prior to the fixed version in Microsoft's March Patch Tuesday
Description The issue is related to improper privilege management in the Windows Error Reporting Service, allowing an attacker to elevate their privileges. The Black Basta ransomware group is suspected of exploiting this vulnerability as a zero-day before a fix was made available. Symantec researchers found an exploit for this bug compiled three months before Microsoft's official patch. The vulnerability was added to CISA KEV, and it is recommended to patch systems promptly to prevent exploitation.
Recommendations For versions prior to the fixed version in Microsoft's March Patch Tuesday, update to the latest version to resolve the issue. As a temporary workaround, consider restricting access to the Windows Error Reporting Service to minimize the risk of exploitation.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2024-02180
CVE-2024-26169

Affected Products

Windows
Windows Error Reporting Service