CVE-2026-24287
7.8Microsoft · Windows Kernel
A path traversal vulnerability in the Windows Kernel allows an authenticated local attacker to achieve privilege escalation.
Executive summary
A vulnerability in the Windows Kernel allows an authenticated local attacker to escalate privileges to a higher level of control.
Vulnerability
This flaw is classified as CWE-73 (External Control of File Name or Path), where improper handling of file paths within the kernel allows an authorized user to gain elevated system privileges. The attack requires the user to already possess local access to the system.
Business impact
Successful exploitation permits a standard user to elevate their privileges, potentially resulting in full system compromise. Given the CVSS score of 7.8, this poses a significant risk to data confidentiality, integrity, and availability, as an attacker could gain administrative control over the affected workstation or server.
Remediation
Immediate Action: Apply the relevant security updates provided by Microsoft in the official security update guide to patch the vulnerable kernel components.
Proactive Monitoring: Monitor system logs for unauthorized attempts to access restricted kernel-level files or unusual process execution patterns that deviate from standard user activity.
Compensating Controls: Ensure that the principle of least privilege is strictly enforced across the environment to limit the impact of a potential local privilege escalation attempt.
Exploitation status
Public Exploit Available: exploit_available (unknown)
Analyst recommendation
Organizations should prioritize the deployment of the March 2026 Microsoft security updates to address this kernel-level vulnerability. While local access is a prerequisite, the ability to escalate privileges poses a severe threat to internal security boundaries, necessitating immediate attention to the patching schedule.
More Microsoft CVEs
Sources
- Windows Kernel Elevation of Privilege Vulnerability Vendor advisory