CVE-2026-69368
massHeap Buffer Overflow in Windows Overlay Filter Enables Local Privilege Escalation
CVE-2026-69368 is a heap-based buffer overflow (CWE-122) in the Windows Overlay Filter, an inbox Windows filesystem filter driver used to service compressed and overlayed file operations. A low-privileged, authenticated local attacker can trigger the overflow by passing crafted input through the filter, with no user interaction required (AV:L/AC:L/PR:L/UI:N). Successful exploitation lets the attacker elevate privileges on the local machine, with high impact on confidentiality, integrity, and availability, effectively bypassing user-to-admin privilege boundaries. Any Windows system that ships the Overlay Filter component is potentially affected; the provided data does not specify exact affected version ranges. Exploitation has not been observed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.2% chance of exploitation within 30 days.
What to do: Apply Microsoft's patch for CVE-2026-69368 as soon as it is available through the normal Windows update channel; the source data does not include a specific KB or fixed-build number. Until patched, prioritize hosts where untrusted or low-privileged users can log on locally or via RDP/VDI, since exploitation requires an authorized local account. No public PoC or in-the-wild exploitation is known, so standard patch cycles are defensible, but treat this flaw as a likely component of multi-step privilege-escalation chains in future attacks.
| Microsoft Windows Overlay Filter (inbox component of Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.