AI description
CVE-2026-24294 is an improper authentication vulnerability found within the Windows SMB Server. This flaw allows an authorized attacker to elevate their privileges locally on an affected system. The issue stems from deficiencies in the SMB Server's authentication procedure, which fails to properly validate authentication credentials or session tokens. To exploit this vulnerability, an attacker must already have local access to the target system, typically with low-level privileges. Once present, they can interact with the SMB Server service using crafted authentication requests to bypass normal privilege restrictions and escalate their access rights, potentially achieving SYSTEM-level control. No user interaction is required for successful exploitation.
- Description
- Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
- Source
- secure@microsoft.com
- NVD status
- Modified
- Products
- windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2022_23h2, windows_server_2025
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- secure@microsoft.com
- CWE-287
- Hype score
- Not currently trending
CVE-2026-24294: Researcher publicly disclosed an NTLM reflection bypass, CVE-2026-24294, with PoC exploit code. It gives SYSTEM on Windows Server 2025. Patch now. #NTLM #NTLMReflection #CVE202624294 #Windows #PrivEsc #Cybersecurity #Infosec
@lyrie_ai
19 Jul 2026
69 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🔴 CVE-2026-24294 | Local NTLM Reflection LPE via SMB Arbitrary Port 10 Mart 2026'da Microsoft tarafından yamalanan bu açık, Windows 11 24H2 / Windows Server 2025'teki SMB Arbitrary Port ve SMB Session Multiplexing davranışını kullanarak NTLM Reflection saldırısını
@ridvanyagli
2 Jul 2026
156 Impressions
0 Retweets
0 Likes
2 Bookmarks
0 Replies
0 Quotes
🔴 CVE-2026-24294 | Local NTLM Reflection LPE via SMB Arbitrary Port 10 Mart 2026'da Microsoft tarafından yamalanan bu açık, Windows 11 24H2 / Windows Server 2025'teki SMB Arbitrary Port ve SMB Session Multiplexing davranışını kullanarak NTLM Reflection saldırısını
@ridvanyagli
2 Jul 2026
16 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Windows-11-24H2/Windows-Server-2025で導入されたSMBの任意ポート接続機能を悪用し、2008年のMS08-068以来ふさがれてきたはずのNTLMリフレクション攻撃をローカルで復活させる手口のPoCエクスプロイトが、CVE-2026-24294に対
@MalwareBibleJP
2 Jul 2026
5216 Impressions
18 Retweets
79 Likes
44 Bookmarks
0 Replies
0 Quotes
NTLM reflection bypass dropped yesterday. CVE-2026-24294. PoC is public. SYSTEM on Windows Server 2025. You know what's funny? Everyone still acts surprised when a 30-year-old auth protocol gets abused. NTLM has been a dumpster fire since the 90s. Kerberos or bust.
@hieyz6838
30 Jun 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 🚨 Researchers disclosed CVE-2026-24294, an NTLM reflection bypass affecting Windows Server 2025, alongside a PoC exploit. The flaw enables SYSTEM privileges. Organizations should patch affected systems immediately. #CyberSecurity #Windows #CVE #InfoSec https://t.co/OuDfb2
@CyberNewst350
29 Jun 2026
14 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Researcher publicly disclosed an NTLM reflection bypass, CVE-2026-24294, with PoC exploit code. It gives SYSTEM on Windows Server 2025. Patch now. #NTLM #NTLMReflection #CVE202624294 #Windows #PrivEsc #Cybersecurity #Infosec https://t.co/upKmDJBUF2 https://t.co/GOALlYOzyg
@Daily_CyberSec
29 Jun 2026
7834 Impressions
32 Retweets
138 Likes
91 Bookmarks
2 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "5AA53525-2EE3-4815-9EEB-49572C16AFC1",
"versionEndExcluding": "10.0.14393.8957",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "CB112C3D-A9C8-41A3-A3DD-ACB42387D087",
"versionEndExcluding": "10.0.14393.8957",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "B2DCF6CD-BA92-4DB2-855E-DE8158AC6B57",
"versionEndExcluding": "10.0.17763.8511",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "40D953EB-E3B1-471A-8400-957984A092EB",
"versionEndExcluding": "10.0.17763.8511",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "35CA4CA1-5EDE-4612-9C17-9AA167F773B9",
"versionEndExcluding": "10.0.19044.7058",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "C18770C8-2B7F-4212-8A4F-1101ABFF4C44",
"versionEndExcluding": "10.0.19044.7058",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "DD070C42-5A71-4D20-B9BA-766565DFC99B",
"versionEndExcluding": "10.0.19044.7058",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "17DCF9E0-A09A-48A3-B281-D22EE76B8062",
"versionEndExcluding": "10.0.19045.7058",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "51FF473A-566D-45FB-868D-03F3907E094A",
"versionEndExcluding": "10.0.19045.7058",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "5FC02001-58B6-4EE4-9552-003F2412ED0C",
"versionEndExcluding": "10.0.19045.7058",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "E8B076BC-42F9-4972-BE73-3874E694CD3A",
"versionEndExcluding": "10.0.22631.6783",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "6E98A971-B530-4289-B7B2-8403BD2DAD07",
"versionEndExcluding": "10.0.22631.6783",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "3381C469-C150-4724-8A53-E11794797D9F",
"versionEndExcluding": "10.0.26100.7979",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "6F1A77F2-59BC-4F92-81A0-2A4E8981FEFB",
"versionEndExcluding": "10.0.26100.7979",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "58F3AA3B-9960-48F9-B013-8CF6BA09893C",
"versionEndExcluding": "10.0.26200.7979",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "F113DAFC-91E5-42C1-A2C3-B9C9286D240B",
"versionEndExcluding": "10.0.26200.7979",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "30606CC6-21D2-4EAC-B568-DABA2786EC61",
"versionEndExcluding": "10.0.28000.1719",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "62E818F7-1053-4CD2-9CCE-EF84D3FA7861",
"versionEndExcluding": "10.0.28000.1719",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
"matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E31E4CDC-138B-41CF-927A-0528A6F605FB",
"versionEndExcluding": "10.0.14393.8957",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2DA555D5-4452-4CD0-AB68-BA175C34EC3A",
"versionEndExcluding": "10.0.17763.8511",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
"matchCriteriaId": "C037CFF5-1294-4724-A28C-42B72A7F0B2E",
"versionEndExcluding": "10.0.20348.4830",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "4A3C9232-BEAB-4D6B-B465-4C4643098054",
"versionEndExcluding": "10.0.25398.2207",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "04014C9F-24B4-4A7A-B2E1-B80EFB7F6D4E",
"versionEndExcluding": "10.0.26100.32463",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]