CVE-2026-69277
massStack-Based Buffer Overflow in Microsoft LSASRV Enables Local Privilege Escalation
CVE-2026-69277 is a stack-based buffer overflow (CWE-121) in the Microsoft Local Security Authority Server component (lsasrv), the Windows service that handles authentication and security policy. The flaw is reachable only locally (AV:L, PR:L, UI:N per CVSS), meaning an attacker must already have a foothold or a valid low-privileged session on the machine and can then trigger the overflow through crafted input processed by lsasrv. A successful exploit allows the authorized attacker to elevate privileges locally, with high impact on confidentiality, integrity, and availability, the kind of bug commonly chained with a remote code execution flaw to take full control of a host. Any Microsoft system running the affected Local Security Authority Server component is in scope, though affected version ranges were not included in the available data and Microsoft's advisory governs the exact list. As of now there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only about a 0.3% probability of exploitation within 30 days (26th percentile), indicating low near-term exploitation risk.
What to do: Obtain Microsoft's remediation for CVE-2026-69277 from the vendor advisory and map it to your Windows builds, prioritizing shared and multi-user systems (RDS hosts, VDI, jump servers) where low-privileged local access is more readily obtained. Until patched, reduce exposure by restricting interactive and remote logon rights to trusted users and ensuring users do not run with administrative privileges. No public PoC or known exploitation exists, so this can follow your standard patch cycle rather than emergency patching, but watch for updates given LSA flaws are frequently chained into full compromise chains.
| Microsoft Local Security Authority Server (lsasrv) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.