oxfemale / CVE-2026-20817
PublicWindows Error Reporting ALPC Elevation of Privilege (CVE-2026-20817) - Proof-of-Concept exploit demonstrating local privilege escalation via WER service.
Proof-of-concept code demonstrating a privilege escalation vulnerability in the Windows Error Reporting service allowing low-privileged users to execute code as SYSTEM.
How It Works
You come across this GitHub project while looking into Windows security flaws and error handling weaknesses.
You read the guide explaining how a regular user can gain top-level system control through a hidden flaw in the error reporting tool.
You set up a safe, isolated old Windows computer without the latest fixes just for trying this out.
You launch the easy-to-run demo program, which reaches out to the error service and runs a sample command with full system powers.
You watch a calculator pop open and check a new file that proves it ran with the highest access level.
Feeling smarter about security, you confirm the flaw works and remind yourself to always update real computers.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.