ZeroHour

CVE-2026-68845

mass

Windows Program Compatibility Assistant Heap Overflow Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-68845 is a heap-based buffer overflow (CWE-122) in the Windows Program Compatibility Assistant Service, maintained by Microsoft. The flaw can be triggered by an attacker who already holds authorized, low-privileged access on a local machine, and it requires no user interaction. Successful exploitation allows the attacker to elevate privileges locally; the high confidentiality, integrity, and availability impact ratings in the CVSS score indicate the compromise can extend to the entire system once elevated privileges are obtained. Any organization or end user running the affected Windows releases is exposed, since the Program Compatibility Assistant ships with Windows by default, though the available data does not enumerate specific affected versions or builds. As of the current data there is no known public proof-of-concept, the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, and its EPSS probability of exploitation within 30 days is 0.3% (25th percentile), so no in-the-wild exploitation is known.

What to do: Apply Microsoft's security update for CVE-2026-68845 across Windows endpoints as soon as it is available, and check the Microsoft advisory for the exact affected Windows editions and builds since they are not listed in the source data. Until patching is complete, reduce risk by limiting local interactive logon and code-execution rights for untrusted or low-privileged users. Given the low EPSS (0.3%) and absence of known exploits, this can be batched with routine high-severity local privilege escalation patching rather than emergency remediation.

Affected
Microsoft Windows Program Compatibility Assistant Service
Estimated exposure
mass≈1 billion+ Windows endpoints (service is built into Windows by default) — The Program Compatibility Assistant is a default component of Windows client operating systems, and Microsoft has reported that Windows runs on over a billion active devices, so the affected population is plausibly in the hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.