ZeroHour

CVE-2026-69277

mass

Stack-Based Buffer Overflow in Microsoft LSASRV Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p26
Published
()
Modified
AI analysis

CVE-2026-69277 is a stack-based buffer overflow (CWE-121) in the Microsoft Local Security Authority Server component (lsasrv), the Windows service that handles authentication and security policy. The flaw is reachable only locally (AV:L, PR:L, UI:N per CVSS), meaning an attacker must already have a foothold or a valid low-privileged session on the machine and can then trigger the overflow through crafted input processed by lsasrv. A successful exploit allows the authorized attacker to elevate privileges locally, with high impact on confidentiality, integrity, and availability, the kind of bug commonly chained with a remote code execution flaw to take full control of a host. Any Microsoft system running the affected Local Security Authority Server component is in scope, though affected version ranges were not included in the available data and Microsoft's advisory governs the exact list. As of now there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only about a 0.3% probability of exploitation within 30 days (26th percentile), indicating low near-term exploitation risk.

What to do: Obtain Microsoft's remediation for CVE-2026-69277 from the vendor advisory and map it to your Windows builds, prioritizing shared and multi-user systems (RDS hosts, VDI, jump servers) where low-privileged local access is more readily obtained. Until patched, reduce exposure by restricting interactive and remote logon rights to trusted users and ensuring users do not run with administrative privileges. No public PoC or known exploitation exists, so this can follow your standard patch cycle rather than emergency patching, but watch for updates given LSA flaws are frequently chained into full compromise chains.

Affected
Microsoft Local Security Authority Server (lsasrv)
Estimated exposure
massorder of hundreds of millions to ~1 billion+ Windows installations (lsasrv ships with Windows; affected versions unspecified) — lsasrv is a core Windows component present on essentially all Windows client and server installs, and Microsoft has publicly cited roughly 1.4 billion active Windows devices, so potential exposure is at the mass scale pending Microsoft's…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-121
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.