CVE-2026-24294

Published Mar 10, 2026

Last updated 2 months ago

CVSS high 7.8
Smb
System

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-24294 is an improper authentication vulnerability found within the Windows SMB Server. This flaw allows an authorized attacker to elevate their privileges locally on an affected system. The issue stems from deficiencies in the SMB Server's authentication procedure, which fails to properly validate authentication credentials or session tokens. To exploit this vulnerability, an attacker must already have local access to the target system, typically with low-level privileges. Once present, they can interact with the SMB Server service using crafted authentication requests to bypass normal privilege restrictions and escalate their access rights, potentially achieving SYSTEM-level control. No user interaction is required for successful exploitation.

Description
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
Source
secure@microsoft.com
NVD status
Modified
Products
windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2022_23h2, windows_server_2025

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-287

Social media

Hype score
Not currently trending
  1. CVE-2026-24294: Researcher publicly disclosed an NTLM reflection bypass, CVE-2026-24294, with PoC exploit code. It gives SYSTEM on Windows Server 2025. Patch now. #NTLM #NTLMReflection #CVE202624294 #Windows #PrivEsc #Cybersecurity #Infosec

    @lyrie_ai

    19 Jul 2026

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. 🔴 CVE-2026-24294 | Local NTLM Reflection LPE via SMB Arbitrary Port 10 Mart 2026'da Microsoft tarafından yamalanan bu açık, Windows 11 24H2 / Windows Server 2025'teki SMB Arbitrary Port ve SMB Session Multiplexing davranışını kullanarak NTLM Reflection saldırısını

    @ridvanyagli

    2 Jul 2026

    156 Impressions

    0 Retweets

    0 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  3. 🔴 CVE-2026-24294 | Local NTLM Reflection LPE via SMB Arbitrary Port 10 Mart 2026'da Microsoft tarafından yamalanan bu açık, Windows 11 24H2 / Windows Server 2025'teki SMB Arbitrary Port ve SMB Session Multiplexing davranışını kullanarak NTLM Reflection saldırısını

    @ridvanyagli

    2 Jul 2026

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Windows-11-24H2/Windows-Server-2025で導入されたSMBの任意ポート接続機能を悪用し、2008年のMS08-068以来ふさがれてきたはずのNTLMリフレクション攻撃をローカルで復活させる手口のPoCエクスプロイトが、CVE-2026-24294に対

    @MalwareBibleJP

    2 Jul 2026

    5216 Impressions

    18 Retweets

    79 Likes

    44 Bookmarks

    0 Replies

    0 Quotes

  5. NTLM reflection bypass dropped yesterday. CVE-2026-24294. PoC is public. SYSTEM on Windows Server 2025. You know what's funny? Everyone still acts surprised when a 30-year-old auth protocol gets abused. NTLM has been a dumpster fire since the 90s. Kerberos or bust.

    @hieyz6838

    30 Jun 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 🚨 Researchers disclosed CVE-2026-24294, an NTLM reflection bypass affecting Windows Server 2025, alongside a PoC exploit. The flaw enables SYSTEM privileges. Organizations should patch affected systems immediately. #CyberSecurity #Windows #CVE #InfoSec https://t.co/OuDfb2

    @CyberNewst350

    29 Jun 2026

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Researcher publicly disclosed an NTLM reflection bypass, CVE-2026-24294, with PoC exploit code. It gives SYSTEM on Windows Server 2025. Patch now. #NTLM #NTLMReflection #CVE202624294 #Windows #PrivEsc #Cybersecurity #Infosec https://t.co/upKmDJBUF2 https://t.co/GOALlYOzyg

    @Daily_CyberSec

    29 Jun 2026

    7834 Impressions

    32 Retweets

    138 Likes

    91 Bookmarks

    2 Replies

    0 Quotes

Configurations