CVE-2026-68884
massHeap-Based Buffer Overflow in Windows Kernel Allows Local Privilege Escalation
CVE-2026-68884 is a heap-based buffer overflow (CWE-122) in the Windows Kernel that Microsoft rates high severity (CVSS 3.1: 7.0). An authorized attacker with low local privileges can trigger the flaw by causing improper handling of kernel memory; the high attack complexity (AC:H) suggests exploitation depends on specific runtime conditions, but no user interaction is required. A successful exploit corrupts adjacent heap memory in kernel space and allows the attacker to elevate privileges locally, gaining full control of the affected system with high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). Any Windows deployment is potentially affected, though the available data does not enumerate the specific affected Windows client or server versions. There are no reports of in-the-wild exploitation, no public proof-of-concept, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-68884 as part of your regular patch cycle; with no known exploitation this is not an emergency, but kernel local privilege escalation flaws are frequently chained with remote code execution bugs, so patch promptly. Because the affected version range is not specified in the available data, verify applicability against Microsoft's advisory and inventory your Windows client and server builds. As interim measures, limit untrusted local accounts on sensitive systems and watch for new signals such as a public PoC, KEV listing, or a rise in EPSS.
| Microsoft Windows (Windows Kernel) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.