ZeroHour

CVE-2026-69459

mass

Heap Overflow in Windows Power Dependency Coordinator Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-69459 is a heap-based buffer overflow (CWE-122) in the Windows Power Dependency Coordinator, a component of Microsoft Windows. An authorized attacker who already has a low-privilege foothold on a local system can trigger the overflow without user interaction, though the precise trigger path is not documented in the available data. Successful exploitation allows the attacker to elevate privileges on the local machine, and Microsoft's CVSS scoring indicates high impact to confidentiality, integrity, and availability on a compromised host. Any Windows installation containing the vulnerable component is potentially affected, but the available data does not enumerate specific affected Windows versions or builds. There are no reports of in-the-wild exploitation, no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation within the next 30 days.

What to do: Install the Microsoft security update that fixes CVE-2026-69459 via Windows Update as soon as practicable, and check Microsoft's advisory for the definitive list of affected Windows versions (not included in the available data). Because exploitation requires local access with low privileges and no user interaction, prioritize hosts where many users or services run with standard accounts, such as RDS/VDI servers, shared workstations, and kiosks, and confirm remediation via Windows update history or winver. No workarounds are specified in the available data.

Affected
Microsoft Windows (Power Dependency Coordinator component)
Estimated exposure
masslikely hundreds of millions of Windows devices (in-box OS component; affected releases unspecified) — Windows' installed base exceeds roughly a billion active devices per public estimates, and the Power Dependency Coordinator ships as part of the OS, so plausible exposure scales to a large share of the Windows fleet until patched, with the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Power Dependency Coordinator allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.