ZeroHour

CVE-2026-69482

mass

Insecure temp file permissions in Windows Error Reporting enable local tampering

CVSS 3.1
7.1 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-69482 is a local vulnerability (CWE-379) in Microsoft's Windows Error Reporting (WER), which creates temporary files in directories that have insecure permissions. An attacker who is already authorized on the system with low-level privileges can exploit this without user interaction, likely by manipulating or replacing temporary files the WER service creates. According to the CVSS score (7.1 high, C:H/I:H/A:N), the attacker gains high-impact tampering and potentially access to sensitive information handled locally, with no availability impact. Because WER is a built-in Windows component, the issue potentially affects the very large installed base of Windows systems; the source data does not specify which Windows versions or builds are affected. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and its EPSS probability of exploitation within 30 days is only 0.3% (24th percentile).

What to do: Apply the Microsoft security update addressing CVE-2026-69482 as soon as it is available through Windows Update, and check Microsoft's advisory to identify affected Windows editions and builds in your estate. Prioritize patching systems where untrusted or low-privileged users have local logon rights, since exploitation requires an authorized local account. In the interim, review ACLs on directories used by WER for temporary files and monitor Microsoft guidance for any exploitation updates.

Affected
Microsoft Windows Error Reporting (component of Microsoft Windows)
Estimated exposure
massplausibly hundreds of millions to ~1.4 billion Windows devices (WER ships by default with Windows) — Windows Error Reporting is an OS-integrated component present by default on Windows client and server installations, so exposure scales with the global Windows installed base, publicly cited by Microsoft at roughly 1.4 billion active…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows an authorized attacker to perform tampering locally.

Weakness
CWE-379
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.