CVE-2026-24291
7.8Microsoft · Windows
A privilege escalation vulnerability exists in the Windows Accessibility Infrastructure due to incorrect permission assignments for the ATBroker process.
Executive summary
A local privilege escalation vulnerability in the Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to gain elevated system privileges.
Vulnerability
This vulnerability, categorized as CWE-732, involves an incorrect permission assignment for a critical resource in the ATBroker component. An attacker who has already gained low-level access to the system can exploit this configuration flaw to elevate their privileges.
Business impact
The ability for a low-privileged user to achieve higher-level system access poses a severe security risk. This flaw could lead to a complete compromise of system integrity, unauthorized access to sensitive data, and the potential for an attacker to maintain persistent, elevated control over affected workstations or servers. Given the CVSS score of 7.8, this vulnerability is considered a high-severity issue that requires prompt administrative attention.
Remediation
Immediate Action: Apply the latest security updates provided by Microsoft for the affected versions of Windows 10 and Windows 11 immediately.
Proactive Monitoring: Review system access logs for anomalous behavior involving the ATBroker.exe process or unexpected privilege escalation events.
Compensating Controls: Implement strict principle of least privilege policies to ensure that standard users have no unnecessary permissions that could facilitate local exploitation.
Exploitation status
Public Exploit Available: Yes, multiple public proofs-of-concept exist on GitHub.
Analyst recommendation
This vulnerability presents a significant risk to organizational security by providing a pathway for attackers to escalate their privileges locally. Organizations should prioritize the deployment of the vendor-supplied security patches across all affected Windows endpoints. Failure to remediate this issue increases the risk of lateral movement and full system compromise by internal or compromised-account threats.