ZeroHour

CVE-2026-69365

mass

Out-of-bounds read in Microsoft Windows lsasrv allows network privilege escalation

CVSS 3.1
8.0 high
EPSS
<1%p50
Published
()
Modified
AI analysis

CVE-2026-69365 is an out-of-bounds read vulnerability (CWE-125) in the Microsoft Local Security Authority Server (lsasrv), the Windows component that handles logon and authentication processing. An authorized, low-privileged attacker can trigger the flaw over the network by getting the target system to process crafted requests to the LSA; the CVSS vector also indicates user interaction is required. Successful exploitation lets the attacker elevate privileges on the targeted system, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 8.0, High). Because lsasrv is a core part of Windows, essentially all Windows systems are potentially affected, although the provided data does not specify exact vulnerable version ranges, so defenders should consult Microsoft's advisory. As of the data available there is no known exploitation: EPSS is 0.7% (about the 50th percentile), the flaw is not in CISA KEV, and no public proof-of-concept exists.

What to do: Install the security update Microsoft has published for this CVE via Windows Update or your patch management tooling, and verify your installed Windows build against the version ranges listed in the MSRC advisory for CVE-2026-69365 (specific fixed versions are not given in this data). In the interim, restrict which accounts can authenticate to sensitive hosts and note that exploitation requires an authorized account plus user interaction, so limiting interactive logon and remote authentication to trusted users reduces risk; monitor LSA/lsasrv activity for anomalies.

Affected
Microsoft Windows - Local Security Authority Server (lsasrv)
Estimated exposure
mass≈1 billion+ Windows devices (lsasrv ships with every Windows installation) — lsasrv is a core Windows authentication component present on essentially all Windows installations and the global Windows installed base exceeds one billion devices; the data provides no specific vulnerable version ranges, so the true…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.