CVE-2026-69612
massLocal Privilege Escalation via Absolute Path Traversal in Windows Error Reporting
CVE-2026-69612 is an absolute path traversal flaw (CWE-36) in the Windows Error Reporting (WER) component of Microsoft Windows. An attacker who already has a low-privileged, authorized account on a machine can leverage the improperly validated absolute path in WER to cause privileged file operations outside the intended location, thereby elevating their privileges locally. Successful exploitation carries high impact to confidentiality, integrity, and availability on the local system (CVSS 3.1 score of 7.8), though the attack vector is local with no user interaction required. Any Windows system containing the WER component is affected — effectively the entire Windows install base — with risk concentrated on multi-user hosts, terminal servers, and systems exposed to Remote Desktop where low-privileged accounts are available. As of now there is no known exploitation: no public proof-of-concept exists, the flaw is not in the CISA KEV catalog, and EPSS assigns it only a 0.4% probability of exploitation within 30 days.
What to do: Track Microsoft's advisory for this CVE and apply the security update for affected Windows versions via Windows Update as soon as it is released; do not skip updates on servers and workstations hosting untrusted or multiple local users. Because exploitation requires an existing low-privileged local account, prioritize patching Remote Desktop-exposed and multi-user systems, and review local account provisioning on shared hosts. Until patched, limit local logon rights to trusted users and monitor WER-related process activity for unexpected privileged file writes.
| Microsoft Windows (Windows Error Reporting component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-36
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.