CVE-2026-69459
massHeap Overflow in Windows Power Dependency Coordinator Enables Local Privilege Escalation
CVE-2026-69459 is a heap-based buffer overflow (CWE-122) in the Windows Power Dependency Coordinator, a component of Microsoft Windows. An authorized attacker who already has a low-privilege foothold on a local system can trigger the overflow without user interaction, though the precise trigger path is not documented in the available data. Successful exploitation allows the attacker to elevate privileges on the local machine, and Microsoft's CVSS scoring indicates high impact to confidentiality, integrity, and availability on a compromised host. Any Windows installation containing the vulnerable component is potentially affected, but the available data does not enumerate specific affected Windows versions or builds. There are no reports of in-the-wild exploitation, no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation within the next 30 days.
What to do: Install the Microsoft security update that fixes CVE-2026-69459 via Windows Update as soon as practicable, and check Microsoft's advisory for the definitive list of affected Windows versions (not included in the available data). Because exploitation requires local access with low privileges and no user interaction, prioritize hosts where many users or services run with standard accounts, such as RDS/VDI servers, shared workstations, and kiosks, and confirm remediation via Windows update history or winver. No workarounds are specified in the available data.
| Microsoft Windows (Power Dependency Coordinator component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Power Dependency Coordinator allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.