ZeroHour

CVE-2026-69377

mass

Missing-Authorization Local Privilege Escalation in Windows Modern Device Management

CVSS 3.1
7.8 high
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-69377 is a missing-authorization flaw (CWE-862) in the Windows Modern Device Management (MDM) component, with Microsoft as the assigned CNA. A locally authenticated attacker with low privileges can trigger the MDM functionality, which fails to properly enforce authorization checks, and requires no user interaction. Successful exploitation elevates the attacker's privileges on the local system, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 7.8, local attack vector). Any Windows system carrying the affected MDM component is potentially affected, but the available data does not specify which Windows versions or edition ranges are impacted. No exploitation is known at this time: there is no public proof-of-concept, the flaw is not listed in CISA KEV, and EPSS estimates only about a 0.3% probability of exploitation within 30 days.

What to do: Because no affected version ranges are given in the available data, check Microsoft's advisory for CVE-2026-69377 and apply the corresponding Windows security update when it is published, prioritizing shared or multi-user endpoints where untrusted users or untrusted code run locally. Until patching is complete, treat endpoints used by low-privileged local users as the priority attack surface and monitor for any public proof-of-concept or in-the-wild reports, which would raise the current EPSS estimate of 0.3%.

Affected
Microsoft Windows Modern Device Management (MDM) component in Windows
Estimated exposure
mass≈1 billion+ Windows devices (MDM component ships in-box with Windows; affected version set unspecified) — Windows runs on roughly a billion-plus devices and the Modern Device Management client ships with the operating system, so an in-box local privilege escalation flaw plausibly touches mass-scale deployments, though Microsoft's…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-862
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.