CVE-2026-69458
massOut-of-Bounds Read Privilege Escalation in Windows BitLocker
CVE-2026-69458 is an out-of-bounds read (CWE-125) in the Windows BitLocker component, rated High with a CVSS 3.1 score of 8.0. Per the published vector, an authorized low-privileged attacker can trigger the flaw over a network with user interaction required, and successful exploitation yields high impact to confidentiality, integrity, and availability, manifested as elevation of privileges on the affected Windows system. Any Windows installation containing the BitLocker component is potentially affected, though the available data does not specify the exact vulnerable Windows versions or builds. There is currently no evidence of exploitation: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.7% probability of exploitation within 30 days (51st percentile). Defenders should treat this as a routine-priority patch once Microsoft's advisory and corresponding Windows updates are available.
What to do: Track Microsoft's advisory for CVE-2026-69458 and apply the corresponding Windows security update as soon as it is released, ensuring BitLocker-enabled hosts (typically Pro, Enterprise, or Server editions) are included in the patch cycle. Until patched, limit interactive and network logon rights to trusted users, since exploitation requires an already-authorized low-privileged attacker and user interaction. No public proof-of-concept or in-the-wild exploitation is known, so emergency mitigation beyond routine patching is not required.
| Microsoft Windows BitLocker | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows BitLocker allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.