CVE-2024-26235: Windows Update Stack Elevation of Privilege Vulnerability
Overview
- Severity
- High (CVSS 7.8)
- CVSS Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Elevation of Privilege
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2024-Apr
- Released
- 2024-04-09
- Last Updated
- 2024-06-26
- EPSS Score
- 1.22% (percentile: 79.1%)
FAQ
What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could overwrite arbitrary file content in the security context of the local system.
Affected Products (1)
Windows
- Windows Server 2022, 23H2 Edition (Server Core installation)
Security Updates (1)
Acknowledgments
Emma Kirkpatrick (<a href=https://twitter.com/carrot_c4k3>@carrot_c4k3</a>)
Revision History
- 2024-04-09: Information published.
- 2024-06-26: Updated acknowledgment. This is an informational change only.