
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24287 is a Windows Kernel privilege escalation vulnerability caused by external control of file name or path (CWE-73), commonly referred to as a path traversal flaw. It allows an authenticated local attacker with low privileges to elevate to SYSTEM-level access without any user interaction. The vulnerability was disclosed and patched on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday. Affected products span Windows 10 (1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2019, 2022, 2022 23H2, and 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The root cause is classified as CWE-73 (External Control of File Name or Path), meaning the Windows Kernel improperly allows user-controlled input to influence file system path resolution in a privileged context. This path traversal weakness can be leveraged by a low-privileged local attacker to manipulate kernel-level file operations, potentially redirecting them to unintended locations and achieving privilege escalation. The attack vector is local, requires low privileges, no user interaction, and has low attack complexity, making it straightforward to exploit once an attacker has a foothold on the system. Related attack patterns include path interception via environment variable manipulation (CAPEC-13, T1574.007) and dynamic linker hijacking (T1574.006) (Microsoft MSRC).
Successful exploitation allows an authenticated local attacker to escalate privileges to SYSTEM level, resulting in complete compromise of the affected host. This grants the attacker the ability to read, modify, or delete sensitive data; install malware or backdoors; create new privileged accounts; and modify system configurations. The high confidentiality, integrity, and availability impact scores reflect the potential for full system takeover, which could serve as a stepping stone for lateral movement within a network (Microsoft MSRC).
Microsoft released patches on March 10, 2026, as part of the March 2026 Patch Tuesday update cycle. Administrators should apply the relevant cumulative updates to bring affected systems to the following minimum build versions: Windows 10 1809 → 10.0.17763.8511; Windows 10 21H2 → 10.0.19044.7058; Windows 10 22H2 → 10.0.19045.7058; Windows 11 23H2 → 10.0.22631.6783; Windows 11 24H2 → 10.0.26100.7979; Windows 11 25H2 → 10.0.26200.7979; Windows 11 26H1 → 10.0.28000.1719; Windows Server 2019 → 10.0.17763.8511; Windows Server 2022 → 10.0.20348.4830; Windows Server 2022 23H2 → 10.0.25398.2207; Windows Server 2025 → 10.0.26100.32463. As a defense-in-depth measure, organizations should enforce the principle of least privilege to limit the blast radius of any potential exploitation (Microsoft MSRC).
CVE-2026-24287 was covered as part of broader March 2026 Patch Tuesday roundups by multiple security vendors and researchers. Tenable, Rapid7, Sophos, and Zero Day Initiative (ZDI) all published patch Tuesday reviews that included this vulnerability among the 83 CVEs addressed that month (Tenable Blog, Rapid7 Blog, Sophos Blog, ZDI Blog). Community and media attention was primarily focused on the two zero-day vulnerabilities patched in the same update cycle, with CVE-2026-24287 receiving moderate attention as a high-severity kernel privilege escalation flaw.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."