CVE-2026-7791 is a local privilege-escalation vulnerability in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows versions before 2.6.2034.0. Improper privilege management, described as a race condition in the log archival process, permits an authenticated non-administrative local user to place arbitrary files in arbitrary locations while bypassing file-system permission protections. Successful exploitation elevates the attacker to the Windows SYSTEM account.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Windows C proof-of-concept for CVE-2026-7791, a local privilege escalation issue in Amazon WorkSpaces Skylight Workspace Config Service. The repo contains only two files: a README describing the vulnerability and usage, and a single C source file implementing the exploit logic. It is not part of a larger exploit framework. The exploit targets a TOCTOU condition in Skylight log rotation under C:\ProgramData\Amazon\Skylight Metrics Agent. According to the README and visible code, the vulnerable service runs as SYSTEM, uses permissive ACLs under C:\ProgramData\Amazon, follows a ROTATE directory junction, performs no file-type validation, and has a narrow race window between an initial file move and later archived-file enumeration. The PoC attempts to win that race by monitoring filesystem activity and deleting/replacing the ROTATE junction at the precise moment the target file appears or enumeration begins. The code defines hardcoded paths for the Skylight base directory and ROTATE directory, plus a default privileged target of C:\Program Files\Amazon\EC2Launch. It accepts a filename and optional target path from the command line, allowing the operator to choose which DLL/file should be planted and where the junction should point. The visible implementation includes a DeleteRotateJunction routine using multiple deletion strategies (RemoveDirectoryW, DeleteFileW, and a cmd.exe rmdir fallback), atomic state tracking with InterlockedCompareExchange, and several monitoring threads. The truncated code clearly shows threads for monitoring the junction target, monitoring the current directory, and a high-frequency 1 ms polling fallback, all prioritized for timing-sensitive race execution. Operationally, the PoC is designed to be run by a low-privileged local user on a vulnerable WorkSpaces host while waiting for scheduled rotation. If successful, the SYSTEM service writes or moves the attacker-supplied DLL into a privileged directory, yielding arbitrary file placement as SYSTEM and enabling follow-on privilege escalation such as DLL hijacking. This is a real exploit PoC rather than a detector, but it is still a research-oriented implementation rather than a fully weaponized framework module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.