CVE-2026-68845
massWindows Program Compatibility Assistant Heap Overflow Enables Local Privilege Escalation
CVE-2026-68845 is a heap-based buffer overflow (CWE-122) in the Windows Program Compatibility Assistant Service, maintained by Microsoft. The flaw can be triggered by an attacker who already holds authorized, low-privileged access on a local machine, and it requires no user interaction. Successful exploitation allows the attacker to elevate privileges locally; the high confidentiality, integrity, and availability impact ratings in the CVSS score indicate the compromise can extend to the entire system once elevated privileges are obtained. Any organization or end user running the affected Windows releases is exposed, since the Program Compatibility Assistant ships with Windows by default, though the available data does not enumerate specific affected versions or builds. As of the current data there is no known public proof-of-concept, the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, and its EPSS probability of exploitation within 30 days is 0.3% (25th percentile), so no in-the-wild exploitation is known.
What to do: Apply Microsoft's security update for CVE-2026-68845 across Windows endpoints as soon as it is available, and check the Microsoft advisory for the exact affected Windows editions and builds since they are not listed in the source data. Until patching is complete, reduce risk by limiting local interactive logon and code-execution rights for untrusted or low-privileged users. Given the low EPSS (0.3%) and absence of known exploits, this can be batched with routine high-severity local privilege escalation patching rather than emergency remediation.
| Microsoft Windows Program Compatibility Assistant Service | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.