CVE-2026-69328
massUntrusted Search Path Local Privilege Escalation in Microsoft Windows Storage
CVE-2026-69328 is an untrusted search path vulnerability (CWE-426) in the Windows Storage component of Microsoft Windows, meaning the component resolves and loads code from directories in the system search path that may not be fully trusted. An attacker who already has limited authorized access to a local machine can plant a malicious executable or library in a searched location, and Windows Storage will load and run it with elevated privileges. Successful exploitation yields local privilege elevation, with the CVSS vector indicating high impact to confidentiality, integrity, and availability on the compromised host. Any Windows system shipping the Storage component is potentially affected; the specific affected Windows versions are not specified in the available data and should be taken from Microsoft's advisory. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69328 through Windows Update as soon as it is available, prioritizing multi-user and terminal-style hosts where local elevation has the greatest impact. As an interim mitigation, verify that directories on the system and application search path are writable only by administrators, since the flaw depends on code being planted in an attacker-writable searched location. Track Microsoft's advisory for the definitive list of affected Windows versions and any updated guidance.
| Microsoft Windows Storage (Windows OS component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-426
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.