CVE-2026-69482
massInsecure temp file permissions in Windows Error Reporting enable local tampering
CVE-2026-69482 is a local vulnerability (CWE-379) in Microsoft's Windows Error Reporting (WER), which creates temporary files in directories that have insecure permissions. An attacker who is already authorized on the system with low-level privileges can exploit this without user interaction, likely by manipulating or replacing temporary files the WER service creates. According to the CVSS score (7.1 high, C:H/I:H/A:N), the attacker gains high-impact tampering and potentially access to sensitive information handled locally, with no availability impact. Because WER is a built-in Windows component, the issue potentially affects the very large installed base of Windows systems; the source data does not specify which Windows versions or builds are affected. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and its EPSS probability of exploitation within 30 days is only 0.3% (24th percentile).
What to do: Apply the Microsoft security update addressing CVE-2026-69482 as soon as it is available through Windows Update, and check Microsoft's advisory to identify affected Windows editions and builds in your estate. Prioritize patching systems where untrusted or low-privileged users have local logon rights, since exploitation requires an authorized local account. In the interim, review ACLs on directories used by WER for temporary files and monitor Microsoft guidance for any exploitation updates.
| Microsoft Windows Error Reporting (component of Microsoft Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows an authorized attacker to perform tampering locally.
- Weakness
- CWE-379
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.