ZeroHour

CVE-2026-69284

mass

Heap Buffer Overflow in Windows DCOM Server Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-69284 is a heap-based buffer overflow (CWE-122) in the Windows DCOM Server component of Microsoft Windows. It is triggered by an authorized attacker who already holds low privileges on the local system and can send crafted input to the DCOM service without any user interaction. Successful exploitation lets the attacker elevate privileges locally, with high impact to confidentiality, integrity and availability on the compromised machine. Any system running an affected Windows release is exposed; the available data does not enumerate the affected Windows version ranges. As of now there is no known exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns it only a 0.2% probability of exploitation in the next 30 days (16th percentile).

What to do: Watch Microsoft's monthly Patch Tuesday release notes and apply the security update addressing CVE-2026-69284 to all supported Windows systems as soon as it is published; do not assume specific versions are unaffected until Microsoft's advisory confirms scope. Because this is a local privilege escalation with no user-interaction requirement, prioritize patching multi-user hosts, terminal servers, and machines frequently logged into by less-trusted accounts, since LPE flaws are commonly chained with remote-code-execution bugs. Track deployment via Windows Update/WSUS/Intune/SCCM compliance reporting and confirm remediation with your vulnerability scanner once detection signatures are available.

Affected
Microsoft Windows (DCOM Server component)
Estimated exposure
mass≈1 billion+ Windows devices (DCOM Server is a core OS component present on effectively all Windows installations) — DCOM Server ships as a built-in component of Microsoft Windows, which runs on well over a billion active devices worldwide per public market-share and device-count estimates, so the potential affected install base is effectively the entire…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.