ZeroHour

CVE-2026-69450

mass

Out-of-bounds read in Windows Error Reporting enables local privilege escalation

CVSS 3.1
7.8 high
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-69450 is an out-of-bounds read (CWE-125) in the Windows Error Reporting (WER) component of Microsoft Windows. A local attacker who is already authenticated with limited user privileges can trigger the flaw with no user interaction required, causing the WER component to read memory beyond intended bounds. Successful exploitation elevates the attacker's privileges on the local machine, with high confidentiality, integrity, and availability impact in the process context, effectively yielding local privilege escalation. Because WER ships as a built-in component of Windows client and server editions, essentially all Windows deployments are potentially affected, though the specific affected version ranges were not included in the available data. There is currently no evidence of exploitation: the flaw is not in CISA's KEV catalog, no public proof-of-concept is known, and EPSS assigns only a 0.3% probability of exploitation within the next 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69450 via Windows Update/WSUS as it becomes available, and check Microsoft's advisory for the exact affected editions, since version ranges were not included in the source data. Because exploitation requires local code execution by an authorized low-privileged user, prioritize patching multi-user systems such as RDS/VDI hosts, shared workstations, and kiosks. Until patched, restrict local code execution by untrusted users and monitor the advisory for changes in affected versions or exploitation status.

Affected
Microsoft Windows (Windows Error Reporting component)
Estimated exposure
mass>1 billion Windows installations (WER ships with every Windows client and server) — Windows Error Reporting is a built-in component present on effectively all Windows installs, and Microsoft has publicly reported over a billion monthly active Windows devices, so the potentially affected base is on the order of a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.