CVE-2026-69325
massHeap buffer overflow in Microsoft JScript enables remote code execution
Microsoft JScript, the Windows scripting engine, contains a heap-based buffer overflow (CWE-122) that can be triggered when the engine processes crafted script content. Per the CVSS vector, a remote, unauthenticated attacker can reach the flaw over a network with no privileges and no user interaction required, though exploitation involves high attack complexity. Successful exploitation yields arbitrary code execution within the affected process, with high impact to confidentiality, integrity, and availability. Any Windows system carrying the JScript engine is affected, with the greatest risk on hosts that evaluate untrusted script input, such as internet-facing servers using legacy ASP, Windows Script Host, or COM automation. There is currently no known public proof of concept, no CISA KEV listing, and EPSS assigns only a 0.6% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69325 through Windows Update once released, prioritizing internet-facing Windows servers that process untrusted script content (legacy ASP, Windows Script Host, COM automation hosts). Until patched, review and restrict services that feed untrusted input into the JScript engine. Check Microsoft's advisory for the definitive affected-version list rather than assuming a specific Windows release.
| Microsoft JScript (Windows scripting engine) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.