{"id":"CVE-2026-20817","title":"Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.","summary":"Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-280"],"vendor":"microsoft","product":"windows_10_21h2","affected":["windows_10_21h2 < 10.0.19044.6809","windows_10_22h2 < 10.0.19045.6809","windows_11_23h2 < 10.0.22631.6491","windows_11_24h2 < 10.0.26100.7623","windows_11_25h2 < 10.0.26200.7623","windows_server_2022 < 10.0.20348.4648","windows_server_2022_23h2 < 10.0.25398.2092","windows_server_2025 < 10.0.26100.32230"],"patched":["windows_10_21h2 10.0.19044.6809","windows_10_22h2 10.0.19045.6809","windows_11_23h2 10.0.22631.6491","windows_11_24h2 10.0.26100.7623","windows_11_25h2 10.0.26200.7623","windows_server_2022 10.0.20348.4648","windows_server_2022_23h2 10.0.25398.2092","windows_server_2025 10.0.26100.32230"],"published":"2026-01-13","updated":"2026-07-30","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20817","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20817","label":"secure@microsoft.com"},{"url":"https://www.vicarius.io/vsociety/posts/cve-2026-20817-detection-script-eop-vulnerabilit-in-windows-error-reporting","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.vicarius.io/vsociety/posts/cve-2026-20817-mitigation-script-eop-vulnerability-in-windows-error-reporting","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.05502,"epssPercentile":0.92428,"ingestedAt":"2026-07-31T06:58:51.360Z","exploits":{"github":2,"githubRepos":["https://github.com/oxfemale/CVE-2026-20817","https://github.com/dwgth4i/CVE-2026-20817"],"checkedAt":"2026-09-23T07:13:54.231Z"},"exploitAvailable":true,"slug":"CVE-2026-20817","body":"## Overview\n\nImproper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.\n\n## Affected\n\n- `windows_10_21h2 < 10.0.19044.6809`\n- `windows_10_22h2 < 10.0.19045.6809`\n- `windows_11_23h2 < 10.0.22631.6491`\n- `windows_11_24h2 < 10.0.26100.7623`\n- `windows_11_25h2 < 10.0.26200.7623`\n- `windows_server_2022 < 10.0.20348.4648`\n- `windows_server_2022_23h2 < 10.0.25398.2092`\n- `windows_server_2025 < 10.0.26100.32230`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `windows_10_21h2 10.0.19044.6809`\n- `windows_10_22h2 10.0.19045.6809`\n- `windows_11_23h2 10.0.22631.6491`\n- `windows_11_24h2 10.0.26100.7623`\n- `windows_11_25h2 10.0.26200.7623`\n- `windows_server_2022 10.0.20348.4648`\n- `windows_server_2022_23h2 10.0.25398.2092`\n- `windows_server_2025 10.0.26100.32230`","depth":"midnight","depthScore":56,"depthScoreParts":{"impact":42.9,"likelihood":1.1,"exploitation":12,"ransomware":0},"changes":[{"seq":5001,"id":"CVE-2026-20817","ts":1788887226928,"field":"exploit_available","old":"false","new":"true"},{"seq":3884,"id":"CVE-2026-20817","ts":1788886357965,"field":"exploit_available","old":"true","new":"false"},{"seq":2706,"id":"CVE-2026-20817","ts":1788883023501,"field":"exploit_available","old":"false","new":"true"},{"seq":1735,"id":"CVE-2026-20817","ts":1788882427659,"field":"exploit_available","old":"true","new":"false"},{"seq":841,"id":"CVE-2026-20817","ts":1788881860607,"field":"exploit_available","old":"false","new":"true"}]}