ZeroHour

CVE-2026-69481

mass

Heap-Based Buffer Overflow in Microsoft Windows Enterprise App Management Allows EoP

CVSS 3.1
8.0 high
EPSS
<1%p51
Published
()
Modified
AI analysis

Microsoft's Windows Enterprise App Management component contains a heap-based buffer overflow (CWE-122). Per the CVSS 3.1 vector, an authorized, low-privileged (authenticated) attacker can trigger the flaw over a network, and exploitation requires some degree of user interaction. Successful exploitation allows the attacker to elevate privileges, with high impact on confidentiality, integrity, and availability. The relevant exposed population is organizations running managed Windows desktops where Enterprise App Management is deployed, typically Intune/MDM-enrolled enterprise fleets. As of this analysis there is no public proof-of-concept, the CVE is not listed in CISA KEV, and EPSS estimates only about a 0.7% probability of exploitation within 30 days.

What to do: Track Microsoft's advisory for CVE-2026-69481 to identify the affected and patched Windows builds (version ranges were not included in the source data) and deploy the fix via Windows Update, WSUS, or Intune. In the interim, restrict what low-privileged users can run from network sources on managed endpoints and monitor for privilege-escalation activity. Given no known exploitation, no public PoC, and low EPSS (~0.7%), treat this as a routine patch-cycle priority rather than an emergency.

Affected
Microsoft Windows (Enterprise App Management component)
Estimated exposure
masslikely 1M+ enterprise-managed Windows endpoints with the Enterprise App Management component present (estimate; exact activation counts unknown) — Enterprise App Management ships with Windows 10/11 Enterprise-class editions deployed in Intune/MDM-managed corporate fleets, and enterprise Windows estates worldwide number in the millions, although the precise number of endpoints where…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Enterprise App Management allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.