PT-2026-24284 · Microsoft · Windows

Chenjian

·

Published

2026-03-10

·

Updated

2026-03-17

·

CVE-2026-24290

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows versions (affected versions not specified)
Description An improper access control issue exists in Windows Projected File System. This allows an authorized attacker to elevate privileges locally. The issue relates to insufficient access restrictions within the Projected File System (ProjFS). Exploitation may allow an attacker to increase their system privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2026-02967
CVE-2026-24290

Affected Products

Windows