ZeroHour

CVE-2026-69493

mass

Unauthenticated RCE via Out-of-Bounds Read in Windows Event Logging Service

CVSS 3.1
9.8 critical
EPSS
<1%p61
Published
()
Modified
AI analysis

CVE-2026-69493 is a memory-safety flaw — an out-of-bounds read (CWE-125, also tagged CWE-122) — in the Windows Event Logging Service. Per the CVSS vector (AV:N/AC:L/PR:N/UI:N), an unauthenticated remote attacker can trigger it directly over the network with no privileges or user interaction required. Successful exploitation yields remote code execution, with the critical 9.8 score reflecting complete impact on confidentiality, integrity, and availability on the compromised host. All Windows systems whose Event Logging Service builds fall within Microsoft's affected range are exposed, but the source data does not specify which Windows versions or KB updates are in scope. As of this analysis there is no known public proof-of-concept, the CVE is not in CISA KEV, and EPSS assigns a ~1.0% probability of exploitation within 30 days (61st percentile), indicating limited but nonzero near-term risk.

What to do: Check Microsoft's advisory for this CVE to identify affected Windows builds and apply the corresponding security update as the primary fix; no workaround is specified in the source data. Until patched, reduce exposure of internet-facing and high-value servers by restricting unauthenticated network access to their remote event-log endpoints (e.g., firewalling RPC reachability), and monitor CISA KEV and PoC trackers, as exploitation risk typically rises once patches are widely deployed.

Affected
Microsoft Windows (Event Logging Service)
Estimated exposure
masspotentially millions of Windows systems (core OS service; affected version scope unspecified) — The Event Logging Service is a core component present on essentially all Windows endpoints and servers (hundreds of millions of installations), so even a partial subset of affected versions plausibly exceeds 1M systems, pending Microsoft's…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122, CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.