ZeroHour

CVE-2026-69391

mass

Stack Buffer Overflow LPE in Windows Broker Infrastructure Service

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69391 is a stack-based buffer overflow (CWE-121) in the Microsoft Windows Broker Infrastructure Service, the Windows component that manages brokered background and inter-process operations. Because the attack vector is local, requires only low privileges, and needs no user interaction, an attacker who can already execute limited code on a Windows machine can trigger the flaw via crafted requests to the service. Successful exploitation allows the attacker to elevate privileges locally to higher (typically SYSTEM-level) rights, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 7.8). Any Windows system where the Broker Infrastructure Service is present is affected; the exact affected Windows version ranges were not specified in the available data and should be taken from Microsoft's advisory. Exploitation status is currently quiet: there is no public proof-of-concept, the flaw is not in CISA KEV, and an EPSS of 0.3% (25th percentile) suggests low probability of near-term exploitation.

What to do: Patch via Windows Update (or WSUS/your endpoint management tooling) as soon as Microsoft's update for CVE-2026-69391 is available, and check Microsoft's advisory for the definitive list of affected Windows versions. Prioritize hosts where untrusted or low-privileged users can run code, such as workstations, terminal/RDS servers, and VDI, since the flaw requires only local low-privilege access. Until patched, restrict local code execution by unprivileged users on sensitive hosts and monitor the Broker Infrastructure Service for anomalous behavior.

Affected
Microsoft Windows (Broker Infrastructure Service)
Estimated exposure
mass≈1 billion+ Windows installations (service is a default Windows component) — The Broker Infrastructure Service ships as a default component of Windows, which by widely cited public estimates runs on well over a billion active devices, so nearly the entire Windows installed base is plausibly in scope pending…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Windows Broker Infrastructure Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-121
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.