CVE-2026-69365
massOut-of-bounds read in Microsoft Windows lsasrv allows network privilege escalation
CVE-2026-69365 is an out-of-bounds read vulnerability (CWE-125) in the Microsoft Local Security Authority Server (lsasrv), the Windows component that handles logon and authentication processing. An authorized, low-privileged attacker can trigger the flaw over the network by getting the target system to process crafted requests to the LSA; the CVSS vector also indicates user interaction is required. Successful exploitation lets the attacker elevate privileges on the targeted system, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 8.0, High). Because lsasrv is a core part of Windows, essentially all Windows systems are potentially affected, although the provided data does not specify exact vulnerable version ranges, so defenders should consult Microsoft's advisory. As of the data available there is no known exploitation: EPSS is 0.7% (about the 50th percentile), the flaw is not in CISA KEV, and no public proof-of-concept exists.
What to do: Install the security update Microsoft has published for this CVE via Windows Update or your patch management tooling, and verify your installed Windows build against the version ranges listed in the MSRC advisory for CVE-2026-69365 (specific fixed versions are not given in this data). In the interim, restrict which accounts can authenticate to sensitive hosts and note that exploitation requires an authorized account plus user interaction, so limiting interactive logon and remote authentication to trusted users reduces risk; monitor LSA/lsasrv activity for anomalies.
| Microsoft Windows - Local Security Authority Server (lsasrv) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.