CVE-2026-69433
massHeap Buffer Overflow in Windows Error Reporting Enables Local Privilege Escalation
CVE-2026-69433 is a heap-based buffer overflow (CWE-122) in Windows Error Reporting (WER), a default component of Microsoft Windows. An attacker who already has a low-privileged account or session on a local machine can trigger the flaw, causing memory corruption in WER that is exploited to execute code outside the normal privilege boundaries. Successful exploitation elevates the attacker's privileges on the local system, yielding high confidentiality, integrity, and availability impact at the host level (CVSS 3.1: 7.8 High). Any Windows deployment with the WER component is potentially affected; the data does not specify which Windows versions are impacted, so defenders should consult Microsoft's advisory for exact version ranges. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only ~0.3%, so no exploitation is known.
What to do: Apply Microsoft's patch for CVE-2026-69433 via Windows Update as soon as it is available, and check Microsoft's advisory to confirm which Windows versions in your estate are in scope. Because this is a local privilege escalation, prioritize hosts where untrusted or low-privileged users get local access, such as shared workstations, RDS/terminal servers, and VDI, and treat it as a post-exploitation escalation risk on any machine where an attacker may already have a foothold. With no public PoC or known in-the-wild exploitation, patching at your normal monthly cadence is reasonable, but do not defer beyond the next patch cycle.
| Microsoft Windows Error Reporting (component of Microsoft Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.