ZeroHour

CVE-2026-68876

mass

Heap Overflow Privilege Elevation in Windows Program Compatibility Assistant Service

CVSS 3.1
8.0 high
EPSS
<1%p49
Published
()
Modified
AI analysis

CVE-2026-68876 is a heap-based buffer overflow (CWE-122) in the Windows Program Compatibility Assistant Service (PcaSvc), a Windows component maintained by Microsoft. Per the CVSS vector, exploitation occurs over a network (AV:N) by an authorized, low-privileged attacker and requires user interaction (UI:R); the available data does not detail the specific trigger path beyond these conditions. A successful exploit elevates the attacker's privileges with high impact on confidentiality, integrity, and availability (C:H/I:H/A:H) on the affected Windows system. Any Windows installation running the Program Compatibility Assistant Service is potentially affected, and the service is enabled by default on modern Windows systems. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS assigns only a 0.7% probability of exploitation in the next 30 days (49th percentile).

What to do: Monitor Microsoft's Security Update Guide for CVE-2026-68876 and apply the Windows security update from the corresponding release as soon as it is published; no version-specific upgrade targets are provided in the available data. Until patched, reduce exposure by restricting low-privileged, user-interactive remote sessions (e.g., RDP) on Windows hosts and confirm the Program Compatibility Assistant Service's running state where hardening policies allow. Since no PoC or in-the-wild exploitation is known, there are no urgent hunt indicators beyond ensuring timely patch compliance.

Affected
Microsoft Windows (Program Compatibility Assistant Service)
Estimated exposure
masshundreds of millions to roughly 1 billion Windows endpoints (PcaSvc is a default Windows service) — The Program Compatibility Assistant Service ships enabled by default on modern Windows client and server installations, and the global Windows installed base is on the order of a billion devices, so the potential affected population is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.