ZeroHour

CVE-2026-69283

mass

Heap Buffer Overflow in Windows CD-ROM Driver Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-69283 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows CD-ROM driver. A local attacker who is already authorized on the system with low-level privileges can trigger the flaw without any user interaction, corrupting memory in the driver. Successful exploitation allows the attacker to elevate privileges on the local machine, gaining execution above their current account's access level. Any Windows system running the affected CD-ROM driver component is affected; the available data does not specify particular Windows version ranges. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation within the next 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69283 via Windows Update on your normal patch cycle, since no public exploit or KEV listing currently exists. Prioritize hosts that expose local logon to multiple or untrusted users (shared workstations, RDS/VDI servers, jump boxes), as exploitation requires existing local access. Verify remediation by confirming the Microsoft update appears in the machine's installed-update history.

Affected
Microsoft Windows (CD-ROM driver component)
Estimated exposure
mass≈1 billion+ Windows installations carry the in-box CD-ROM driver — The CD-ROM driver is a standard in-box Windows component present on essentially all Windows installations, and Windows is publicly estimated to run on roughly 1.4 billion devices, though actual exploitability additionally requires local…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.