ZeroHour

CVE-2026-69458

mass

Out-of-Bounds Read Privilege Escalation in Windows BitLocker

CVSS 3.1
8.0 high
EPSS
<1%p51
Published
()
Modified
AI analysis

CVE-2026-69458 is an out-of-bounds read (CWE-125) in the Windows BitLocker component, rated High with a CVSS 3.1 score of 8.0. Per the published vector, an authorized low-privileged attacker can trigger the flaw over a network with user interaction required, and successful exploitation yields high impact to confidentiality, integrity, and availability, manifested as elevation of privileges on the affected Windows system. Any Windows installation containing the BitLocker component is potentially affected, though the available data does not specify the exact vulnerable Windows versions or builds. There is currently no evidence of exploitation: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.7% probability of exploitation within 30 days (51st percentile). Defenders should treat this as a routine-priority patch once Microsoft's advisory and corresponding Windows updates are available.

What to do: Track Microsoft's advisory for CVE-2026-69458 and apply the corresponding Windows security update as soon as it is released, ensuring BitLocker-enabled hosts (typically Pro, Enterprise, or Server editions) are included in the patch cycle. Until patched, limit interactive and network logon rights to trusted users, since exploitation requires an already-authorized low-privileged attacker and user interaction. No public proof-of-concept or in-the-wild exploitation is known, so emergency mitigation beyond routine patching is not required.

Affected
Microsoft Windows BitLocker
Estimated exposure
mass≈100M+ Windows installations (BitLocker ships with all supported Windows Pro, Enterprise, and Server editions) — BitLocker is built into every supported Windows Pro, Enterprise, Education, and Server edition, a combined installed base of hundreds of millions of devices, so the potentially affected population is on the order of 10^8 systems, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows BitLocker allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.