
Educational Proof of Concept (PoC) for CVE-2023-36874 — Windows Error Reporting (WER) Local Privilege Escalation vulnerability.
An educational and defensive research implementation of the CVE-2023-36874 vulnerability, demonstrating a Local Privilege Escalation (LPE) flaw within the Windows Error Reporting (WER) component.
This repository and the provided source code are intended strictly for educational purposes, security research, and defensive auditing. Do not run this code on production systems or environments without explicit authorization. The author accepts no liability for any misuse, damage, or illegal activity conducted with this material.
CVE-2023-36874 is a logical privilege escalation vulnerability in Windows Error Reporting (WER).
A low-privileged attacker can exploit this flaw by manipulating the Windows Object Manager namespace. By creating a custom symbolic link (\??\C:) inside the local session directory, the attacker can redirect file access requests intended for the root drive.
When a highly privileged service (NT AUTHORITY\SYSTEM) triggers error reporting tasks using specific, undocumented COM interfaces (such as IErcLuaSupport), it improperly executes files from the redirected path. This allows a user-controlled binary (wermgr.exe) to be executed with SYSTEM privileges.
main.cpp — The main C++ source code responsible for environment setup, Object Manager symlink creation, and COM interaction.exploit.exe (Placeholder) — The target payload binary that will be spawned by the privileged service.main.cpp to the source files.x86 (Win32) to x64. The exploit relies on 64-bit system path resolution.Ctrl + Shift + B).When executed, the program performs the following operations behind the scenes:
C:\ProgramData and prepares a mirror directory structure in C:\Users\Public\test\Windows\System32.NtCreateSymbolicLinkObject to reroute local session drive C: queries to the custom Public\test folder.CLSID_ERCLuaSupport.SubmitReport(). The system attempts to launch C:\Windows\System32\wermgr.exe but gets redirected to the payload.The binary runs silently in the background.
0 and your payload will execute in the context of NT AUTHORITY\SYSTEM.-1.This issue was formally addressed by Microsoft in the July 2023 Patch Tuesday update cycle.
To mitigate this and similar vulnerabilities: