ZeroHour

CVE-2026-69368

mass

Heap Buffer Overflow in Windows Overlay Filter Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-69368 is a heap-based buffer overflow (CWE-122) in the Windows Overlay Filter, an inbox Windows filesystem filter driver used to service compressed and overlayed file operations. A low-privileged, authenticated local attacker can trigger the overflow by passing crafted input through the filter, with no user interaction required (AV:L/AC:L/PR:L/UI:N). Successful exploitation lets the attacker elevate privileges on the local machine, with high impact on confidentiality, integrity, and availability, effectively bypassing user-to-admin privilege boundaries. Any Windows system that ships the Overlay Filter component is potentially affected; the provided data does not specify exact affected version ranges. Exploitation has not been observed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.2% chance of exploitation within 30 days.

What to do: Apply Microsoft's patch for CVE-2026-69368 as soon as it is available through the normal Windows update channel; the source data does not include a specific KB or fixed-build number. Until patched, prioritize hosts where untrusted or low-privileged users can log on locally or via RDP/VDI, since exploitation requires an authorized local account. No public PoC or in-the-wild exploitation is known, so standard patch cycles are defensible, but treat this flaw as a likely component of multi-step privilege-escalation chains in future attacks.

Affected
Microsoft Windows Overlay Filter (inbox component of Windows)
Estimated exposure
massRoughly a billion or more Windows installations carry the affected inbox component (estimate based on the installed base) — Microsoft has publicly reported over 1.4 billion monthly active Windows devices, and the Overlay Filter driver ships as a standard component of current Windows releases, so the potential exposure is mass-scale even though exploitation…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.