ZeroHour

CVE-2026-68850

mass

Heap Buffer Overflow in Microsoft Account Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-68850 is a heap-based buffer overflow (CWE-122) in the Microsoft Account component, rated High severity by Microsoft (CVSS 3.1: 7.8). An attacker who is already authorized on the machine with low-level privileges can trigger the overflow via the Microsoft Account component without any user interaction. Successful exploitation allows the attacker to elevate privileges locally, extending control beyond the compromised account's rights, with high impact on confidentiality, integrity, and availability. Any Windows installation that includes the affected Microsoft Account component is affected; because exploitation requires an existing local foothold, risk is highest on multi-user systems, shared workstations, and hosts where attackers may already be present. No public proof-of-concept is known, the flaw is not in CISA's KEV, and an EPSS of 0.2% (15th percentile) indicates no known exploitation at this time.

What to do: Apply Microsoft's security update for the Microsoft Account component when released, and check Microsoft's advisory for the specific affected Windows versions and update packages. In the meantime, prioritize hosts with multiple local or limited accounts (shared workstations, RDS/session hosts) and check for signs of existing local compromise, since this flaw primarily benefits attackers who already hold a low-privileged foothold.

Affected
Microsoft Account (Windows component)
Estimated exposure
masshundreds of millions of Windows devices (the Microsoft Account component ships with Windows) — The Microsoft Account sign-in component is bundled with Windows, which runs on over a billion active devices worldwide, so the potentially affected installed base is plausibly in the hundreds of millions of machines, though actual…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Account allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.