ZeroHour

CVE-2026-69492

mass

Heap Overflow in Windows Partition Management Driver Allows Local Privilege Escalation

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69492 is a heap-based buffer overflow (CWE-122) in Microsoft's Windows Partition Management Driver. The CVSS vector (AV:L/AC:H/PR:L/UI:N) indicates exploitation requires local access and an already-authorized low-privileged user, involves high attack complexity, and needs no user interaction; the specific trigger path has not been publicly detailed. A successful exploit allows elevation of privileges, with high confidentiality, integrity, and availability impact consistent with SYSTEM/kernel-level compromise of the local machine. Affected Windows versions are not specified in the available data; the Partition Management Driver is an in-box Windows component, so broadly deployed Windows installations are potentially in scope. There is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns a 0.3% probability of exploitation within 30 days (17th percentile), so no exploitation is currently known.

What to do: Install the Microsoft Windows security update addressing CVE-2026-69492 via Windows Update, as no workaround is documented. Given high attack complexity and no public PoC or known exploitation, standard patch cadence is defensible, but prioritize hosts where multiple local users or untrusted code run. Verify remediation by confirming the corresponding Windows update is applied across endpoint fleets.

Affected
Microsoft Windows Partition Management Driver
Estimated exposure
masshundreds of millions of Windows installations (in-box driver; Windows install base exceeds 1 billion devices) — Because the Partition Management Driver ships in-box with Windows, the plausible exposure ceiling is the global Windows installed base (on the order of 1 billion+ devices), putting affected installations in the hundreds of millions, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.