Researchers disclosed CVE-2026-20817, a local privilege escalation flaw in the Windows Error Reporting (WER) service that allows a low-privileged user to obtain SYSTEM privileges by sending a crafted ALPC message to \WindowsErrorReportingServicePort. The bug resides in WerSvc.dll and affects the SvcElevatedLaunch code path, where user-controlled data from a file-mapping-backed buffer can be passed as command-line arguments when the service launches WerFault.exe with CreateProcessAsUserW under SYSTEM context.
Patch analysis showed Microsoft mitigated the issue by effectively disabling the vulnerable SvcElevatedLaunch feature rather than rewriting the logic, with the patched path returning 0x80004005 (E_FAIL). Researchers produced a proof of concept demonstrating SYSTEM-context WerFault.exe execution with attacker-controlled arguments, although full arbitrary code execution would require additional Windows internals techniques; they also noted operational constraints such as the WER service needing to be running and possible Microsoft Defender detection because the behavior resembles parent process ID spoofing. Reports further warned that fake and potentially malicious GitHub proof-of-concept repositories for CVE-2026-20817 are already circulating.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Follow-on reporting highlighted that potentially malicious fake proof-of-concept repositories for CVE-2026-20817 had appeared on GitHub after public disclosure of the vulnerability details. The warning accompanied broader coverage of the exploit mechanics and Microsoft's mitigation approach.
A researcher published patch analysis and exploitation details for CVE-2026-20817, showing how crafted messages sent to \WindowsErrorReportingServicePort could reach SvcElevatedLaunch and launch WerFault.exe as SYSTEM with user-controlled arguments. The write-up included a proof of concept and noted operational constraints such as the WER service needing to be running and possible Microsoft Defender detection.
Microsoft addressed CVE-2026-20817, a local privilege escalation flaw in the Windows Error Reporting service, by effectively disabling the vulnerable SvcElevatedLaunch functionality so the patched code path returns E_FAIL. The issue allowed a low-privileged local user to trigger SYSTEM-context WerFault.exe execution via crafted ALPC messages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.