ZeroHour

CVE-2026-69438

mass

Numeric Type Conversion Flaw in Microsoft JScript Enables Network RCE

CVSS 3.1
8.1 high
EPSS
<1%p51
Published
()
Modified
AI analysis

Microsoft JScript contains a flaw (CWE-681, incorrect conversion between numeric types) that mishandles a numeric type conversion, and an unauthenticated attacker who can get the engine to process specially crafted input over a network can exploit it to execute code. The attack vector is network-based with no privileges or user interaction required, but the high attack-complexity metric means exploitation depends on conditions the attacker does not fully control. A successful attack yields high impact to confidentiality, integrity, and availability — typically code execution in the context of the process hosting the JScript engine. Affected deployments include any product that bundles the JScript engine, which ships as a component of Microsoft Windows, though the available advisory data does not enumerate specific product versions. Exploitation status: no known exploitation, no public proof-of-concept, not listed in CISA KEV, and EPSS assigns a 0.7% probability of exploitation within 30 days.

What to do: Apply the Microsoft security update for CVE-2026-69438 as soon as it is published, via Windows Update or Microsoft's advisory, and verify patch status across the Windows estate once affected versions are enumerated. Until patched, review where the JScript engine (e.g., Windows Script Host or legacy scripting paths) processes untrusted, network-supplied input and restrict or harden those code paths. Given no known exploitation and no public PoC, routine patch-cadence prioritization is reasonable rather than emergency response.

Affected
Microsoft JScript
Estimated exposure
mass~1 billion+ devices (JScript engine is bundled with Windows) — The JScript engine ships with Microsoft Windows, whose installed base is on the order of a billion devices per public deployment estimates, so potential exposure is mass-scale even though only code paths that feed untrusted input to the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect conversion between numeric types in Microsoft JScript allows an unauthorized attacker to execute code over a network.

Weakness
CWE-681
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.