CVE-2026-69421
massInteger Underflow Local Privilege Escalation in Microsoft Windows Kernel Mode Driver
CVE-2026-69421 is an integer underflow (wrap or wraparound, CWE-191) in a Windows kernel-mode driver that Microsoft rates High (7.8) with a local attack vector, low attack complexity, and low privileges required. If the underflow produces an undersized buffer or length value, it can lead to heap-based buffer overflow conditions (CWE-122) when the driver processes the miscalculated data. An authorized local attacker — meaning a user or process already able to run code on the machine — can trigger the flaw and gain elevated privileges, with high impact on confidentiality, integrity, and availability, typically achieving kernel- or SYSTEM-level access. All Windows systems running the affected kernel-mode driver component are exposed, with the affected version ranges defined by Microsoft's advisory. There is currently no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.3% probability of exploitation within 30 days, so no exploitation is known at this time.
What to do: Apply Microsoft's security update for CVE-2026-69421 as soon as it is released and check the Microsoft advisory for the exact affected Windows versions and builds before prioritizing rollout. Patch shared and multi-user endpoints and servers first, since any local user able to run untrusted code can exploit the flaw. No public PoC or in-the-wild exploitation is known yet, but monitor for PoC releases and add the CVE to your patch-tracking once Microsoft publishes affected-build details.
| Microsoft Windows (Kernel Mode Driver component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer underflow (wrap or wraparound) in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-122, CWE-191
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.