
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24283 is a heap-based buffer overflow vulnerability in the Windows File Server component that allows an authenticated local attacker with low privileges to elevate privileges to SYSTEM level. It was disclosed on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday security update cycle. Affected products include Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025 and Windows Server 2022 23H2. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Microsoft MSRC).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), occurring within the Windows File Server component. An authorized local attacker with low privileges can trigger the overflow without any user interaction, and the changed scope indicator in the CVSS vector reflects that successful exploitation breaks AppContainer sandbox isolation — allowing the attacker to affect resources beyond the vulnerable component's security boundary. The attack vector is local, requires low privileges, and has low complexity, making it straightforward to exploit once an attacker has a foothold on the system. No public proof-of-concept or detailed technical write-up has been identified at this time (Microsoft MSRC, Feedly).
Successful exploitation grants the attacker SYSTEM-level access on the compromised host, achieving full compromise of confidentiality, integrity, and availability. A notable consequence is the breaking of AppContainer sandbox isolation, allowing attackers to access sensitive data and processes outside their intended security boundary. This poses heightened risk in multi-tenant and shared infrastructure environments, where privilege escalation could facilitate lateral movement and enterprise-wide compromise (Microsoft MSRC).
Microsoft released patches on March 10, 2026, as part of the March 2026 Patch Tuesday update. Administrators should apply updates to bring affected systems to the following minimum versions: Windows 11 26H1 to 10.0.28000.1719 or later, Windows 11 25H2 to 10.0.26200.7979 or later, Windows 11 24H2 to 10.0.26100.7979 or later, Windows Server 2025 to 10.0.26100.32463 or later, and Windows Server 2022 23H2 to 10.0.25398.2207 or later. Prioritize patching Windows Server systems in multi-tenant or shared environments given the potential for lateral movement. No configuration-based workarounds have been published by Microsoft (Microsoft MSRC).
The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Rapid7, Zero Day Initiative, Sophos, and Lansweeper, which noted the overall release addressed 79 vulnerabilities including two zero-days. Security researchers highlighted the changed scope and SYSTEM-level impact as factors warranting prioritized patching, particularly for server environments. No specific individual researcher commentary or significant social media controversy specific to this CVE has been identified (ZDI Blog, Rapid7, Sophos).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."