KEV · Actively exploited
CVE-2024-26169
HIGH 7.8
KEV
Windows Error Reporting Service Elevation of Privilege Vulnerability
EPSS
35.15%
moderate exploit risk
percentile 97.1%
CISA Known Exploited Vulnerability
- Added to KEV
- 2024-06-13
- Remediation deadline
- 2024-07-04
- Required action
- Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
- Ransomware
- Yes, known ransomware campaign
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Fixed in Windows Server 2022 (Server Core installation) 10.0.20348.2340 Windows Server 2022 10.0.25398.763 Windows Server 2019 (Server Core installation) 10.0.17763.5576 Windows Server 2019 10.0.17763.5576 Windows Server 2016 (Server Core installation) 10.0.14393.6796 Windows Server 2016 10.0.14393.6796 Windows 11 23H2 · 2023-H2 10.0.22631.3296 Windows 11 22H2 · 2022-H2 10.0.22621.3296 Windows 11 21H2 · 2021-H2 10.0.22000.2836 Windows 10 22H2 · 2022-H2 10.0.19045.4170 Windows 10 21H2 · 2021-H2 10.0.19044.4170 Windows 10 1809 · 2018-09 10.0.17763.5576 Windows 10 1607 · 2016-07 10.0.14393.6796