CVE-2026-68876
massHeap Overflow Privilege Elevation in Windows Program Compatibility Assistant Service
CVE-2026-68876 is a heap-based buffer overflow (CWE-122) in the Windows Program Compatibility Assistant Service (PcaSvc), a Windows component maintained by Microsoft. Per the CVSS vector, exploitation occurs over a network (AV:N) by an authorized, low-privileged attacker and requires user interaction (UI:R); the available data does not detail the specific trigger path beyond these conditions. A successful exploit elevates the attacker's privileges with high impact on confidentiality, integrity, and availability (C:H/I:H/A:H) on the affected Windows system. Any Windows installation running the Program Compatibility Assistant Service is potentially affected, and the service is enabled by default on modern Windows systems. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS assigns only a 0.7% probability of exploitation in the next 30 days (49th percentile).
What to do: Monitor Microsoft's Security Update Guide for CVE-2026-68876 and apply the Windows security update from the corresponding release as soon as it is published; no version-specific upgrade targets are provided in the available data. Until patched, reduce exposure by restricting low-privileged, user-interactive remote sessions (e.g., RDP) on Windows hosts and confirm the Program Compatibility Assistant Service's running state where hardening policies allow. Since no PoC or in-the-wild exploitation is known, there are no urgent hunt indicators beyond ensuring timely patch compliance.
| Microsoft Windows (Program Compatibility Assistant Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.