ZeroHour

CVE-2026-69325

mass

Heap buffer overflow in Microsoft JScript enables remote code execution

CVSS 3.1
8.1 high
EPSS
<1%p49
Published
()
Modified
AI analysis

Microsoft JScript, the Windows scripting engine, contains a heap-based buffer overflow (CWE-122) that can be triggered when the engine processes crafted script content. Per the CVSS vector, a remote, unauthenticated attacker can reach the flaw over a network with no privileges and no user interaction required, though exploitation involves high attack complexity. Successful exploitation yields arbitrary code execution within the affected process, with high impact to confidentiality, integrity, and availability. Any Windows system carrying the JScript engine is affected, with the greatest risk on hosts that evaluate untrusted script input, such as internet-facing servers using legacy ASP, Windows Script Host, or COM automation. There is currently no known public proof of concept, no CISA KEV listing, and EPSS assigns only a 0.6% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69325 through Windows Update once released, prioritizing internet-facing Windows servers that process untrusted script content (legacy ASP, Windows Script Host, COM automation hosts). Until patched, review and restrict services that feed untrusted input into the JScript engine. Check Microsoft's advisory for the definitive affected-version list rather than assuming a specific Windows release.

Affected
Microsoft JScript (Windows scripting engine)
Estimated exposure
masshundreds of millions to 1B+ Windows devices (JScript ships as a built-in component of Windows) — JScript is a default component of Microsoft Windows, so the potentially affected installed base approximates the global Windows fleet, though practical network exposure concentrates on the smaller subset of internet-reachable servers that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.