ZeroHour

CVE-2026-69436

mass

Heap Buffer Overflow in Windows Error Reporting Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-69436 is a heap-based buffer overflow (CWE-122) in the Windows Error Reporting (WER) component of Microsoft Windows. An attacker who already holds valid low-privileged access to a machine can trigger the flaw locally with no user interaction required (AV:L/AC:L/PR:L/UI:N), corrupting heap memory used by WER. Successful exploitation lets the attacker elevate their privileges on the local system, producing the high confidentiality, integrity, and availability impact reflected in the 7.8 (high) CVSS score. Any Windows installation containing the affected WER component is potentially exposed; Microsoft, the assigning CNA, has not published specific affected version ranges in the available data. No public proof-of-concept is known, the flaw is not in CISA's KEV, and its EPSS score of 0.3% (28th percentile) indicates low near-term exploitation risk.

What to do: Apply Microsoft's security update for CVE-2026-69436 through the normal patch cycle and track Microsoft's advisory for the fixed builds, since no patched version numbers appear in the available data. Until patched, reduce risk on high-value hosts (terminal servers, VDI images, shared workstations) by limiting interactive logon and standard-user access, as exploitation requires an authorized local user. Given the absence of a public PoC or in-the-wild exploitation, emergency patching is not indicated, but prioritize multi-user systems where local privilege escalation yields the most access.

Affected
Microsoft Windows Error Reporting (component of Microsoft Windows)
Estimated exposure
mass≈1 billion+ Windows devices (WER ships as a default component of Windows) — Windows Error Reporting is installed by default on essentially all Windows client and server systems, and Windows runs on well over a billion active devices worldwide, so the potential installed base is on the order of a billion machines.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.