PT-2026-24288 · Microsoft · Windows

·

CVE-2026-24294

·

Published

2026-03-10

·

Updated

2026-07-19

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Server 2025
Description Improper authentication in the Windows SMB Server allows an authorized attacker to elevate privileges locally. This issue involves an NTLM reflection bypass, which can be used to obtain SYSTEM privileges on the affected system.
Recommendations Update Windows Server 2025 to the latest patched version.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02974
CVE-2026-24294

Affected Products

Windows