PT-2024-2247 · Microsoft · Windows Error Reporting Service+1
Naceri
·
Published
2024-03-12
·
Updated
2025-09-17
·
CVE-2024-26169
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Error Reporting Service versions prior to the fixed version in Microsoft's March Patch Tuesday
Description
The issue is related to improper privilege management in the Windows Error Reporting Service, allowing an attacker to elevate their privileges. The Black Basta ransomware group is suspected of exploiting this vulnerability as a zero-day before a fix was made available. Symantec researchers found an exploit for this bug compiled three months before Microsoft's official patch. The vulnerability was added to CISA KEV, and it is recommended to patch systems promptly to prevent exploitation.
Recommendations
For versions prior to the fixed version in Microsoft's March Patch Tuesday, update to the latest version to resolve the issue. As a temporary workaround, consider restricting access to the Windows Error Reporting Service to minimize the risk of exploitation.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows
Windows Error Reporting Service