ZeroHour

CVE-2026-69371

mass

Heap Buffer Overflow EoP in Microsoft Windows Overlay Filter

CVSS 3.1
8.0 high
EPSS
<1%p51
Published
()
Modified
AI analysis

CVE-2026-69371 is a heap-based buffer overflow (CWE-122) in the Windows Overlay Filter, the Windows component that handles overlay/compressed file-system layers. According to Microsoft's advisory, an authorized (already authenticated) attacker can trigger the flaw over a network, with the CVSS vector indicating low privileges and user interaction are required for successful exploitation. A successful attacker gains elevation of privilege on the target Windows system, with high impact to confidentiality, integrity, and availability (CVSS 3.1 score of 8.0, high). Any Windows deployment that includes the Overlay Filter component is in scope; Microsoft's advisory governs the exact affected version ranges, which are not enumerated in the available data. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.7% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69371 as soon as it is available through Windows Update, prioritizing multi-user hosts, servers, and systems with remotely accessible accounts since exploitation requires an authorized network path and user interaction. Review the Microsoft advisory for the precise affected version ranges and confirm via your patch-management reporting that affected hosts have received the current cumulative update. No workaround is documented in the available data, so limit low-privileged accounts' access to Windows endpoints as a compensating control while patching completes.

Affected
Microsoft Windows (Overlay Filter component)
Estimated exposure
mass≈1,000,000,000+ Windows endpoints (Overlay Filter ships with the OS) — Windows runs on well over a billion devices worldwide with dominant desktop market share, and the Overlay Filter is an OS-shipped component, so the potential installed base is on the order of a billion systems even though only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.