ZeroHour

CVE-2026-69421

mass

Integer Underflow Local Privilege Escalation in Microsoft Windows Kernel Mode Driver

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69421 is an integer underflow (wrap or wraparound, CWE-191) in a Windows kernel-mode driver that Microsoft rates High (7.8) with a local attack vector, low attack complexity, and low privileges required. If the underflow produces an undersized buffer or length value, it can lead to heap-based buffer overflow conditions (CWE-122) when the driver processes the miscalculated data. An authorized local attacker — meaning a user or process already able to run code on the machine — can trigger the flaw and gain elevated privileges, with high impact on confidentiality, integrity, and availability, typically achieving kernel- or SYSTEM-level access. All Windows systems running the affected kernel-mode driver component are exposed, with the affected version ranges defined by Microsoft's advisory. There is currently no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.3% probability of exploitation within 30 days, so no exploitation is known at this time.

What to do: Apply Microsoft's security update for CVE-2026-69421 as soon as it is released and check the Microsoft advisory for the exact affected Windows versions and builds before prioritizing rollout. Patch shared and multi-user endpoints and servers first, since any local user able to run untrusted code can exploit the flaw. No public PoC or in-the-wild exploitation is known yet, but monitor for PoC releases and add the CVE to your patch-tracking once Microsoft publishes affected-build details.

Affected
Microsoft Windows (Kernel Mode Driver component)
Estimated exposure
mass>1 billion Windows devices (kernel-mode driver LPEs affect essentially all desktop and server installs of the affected builds) — Microsoft has publicly reported over 1.4 billion monthly active Windows devices, and local privilege-escalation flaws in shared kernel components apply broadly across Windows desktop and server deployments, though the specific affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer underflow (wrap or wraparound) in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-122, CWE-191
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.