CVE-2026-69480
massWindows Partition Management Driver Heap Overflow Enables Local Privilege Escalation
CVE-2026-69480 is a heap-based buffer overflow (CWE-122) in the Windows Partition Management Driver, an in-box kernel component of Microsoft Windows. An authorized local attacker, requiring only low privileges per the CVSS vector (AV:L/PR:L, no user interaction), can send input that the driver fails to properly bounds-check, overflowing a heap buffer. Successful exploitation allows elevation of privileges with high impact on confidentiality, integrity, and availability, meaning an attacker could gain elevated (likely kernel-level or SYSTEM) access on the targeted machine. Any Windows environment is in scope — workstations, servers, and multi-user systems where untrusted users hold local logon rights — though the specific affected Windows builds are enumerated in Microsoft's advisory rather than in this data. There is currently no known exploitation: no public proof-of-concept, not listed in CISA KEV, and a low EPSS of 0.3% (25th percentile), indicating low predicted likelihood of exploitation within 30 days.
What to do: Install Microsoft's security update addressing CVE-2026-69480 once published, checking Microsoft's advisory for the affected builds in your estate. Prioritize multi-user systems where any low-privileged account can log on locally (terminal servers, shared workstations, jump hosts), since local logon rights are the prerequisite for exploitation. With no public PoC and not in CISA KEV, this can be handled on a normal Patch Tuesday cycle rather than as an emergency, but do not defer it — local EoP flaws are commonly chained with other bugs after public disclosure.
| Microsoft Windows Partition Management Driver (in-box Windows component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.