CVE-2024-26169 is a local elevation-of-privilege vulnerability in the Windows Error Reporting Service. Available reporting indicates the issue can be abused through Windows Error Reporting behavior involving registry key creation and Image File Execution Options handling for WerFault.exe. The exploit path described publicly abuses the creation of registry subkeys with ownership and permission characteristics that allow a low-privileged user to influence the debugger configuration for the error-reporting process, causing attacker-controlled code to be launched in a higher-privileged context. Successful exploitation results in escalation from a low-privileged local account to SYSTEM on affected Windows systems.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Metasploit module (cve_2017_11882.rb) that exploits CVE-2017-11882, a remote code execution vulnerability in Microsoft Office Word's Equation Editor. The exploit works by generating a malicious RTF file (using a template, cve-2017-11882.rtf) that, when opened by a vulnerable user, triggers mshta.exe to fetch and execute an HTA payload from the attacker's HTTP server. The module is fully integrated with Metasploit, allowing the attacker to select and deliver any supported payload. The repository structure is simple: a README with usage instructions, the RTF template, and the Ruby Metasploit module. The main attack vectors are file format (malicious RTF) and network (HTTP delivery of the HTA payload). The exploit is weaponized, as it is part of the Metasploit framework and supports customizable payloads.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows Error Reporting (WER) Service local elevation-of-privilege vulnerability that the content says Black Basta exploited, with exploit variants apparently in use before public disclosure and patching.
A Windows Error Reporting Service vulnerability that the report states Black Basta exploits during operations (notably for privilege escalation per the table’s CWE-269 association).
A vulnerability in the Microsoft Windows Error Reporting Service, exploited by ransomware groups for privilege escalation.
A Windows Error Reporting Service privilege escalation vulnerability that may have been exploited as a zero-day by the Cardinal/Black Basta group to gain administrative privileges on affected systems.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.