CVE-2026-69493
massUnauthenticated RCE via Out-of-Bounds Read in Windows Event Logging Service
CVE-2026-69493 is a memory-safety flaw — an out-of-bounds read (CWE-125, also tagged CWE-122) — in the Windows Event Logging Service. Per the CVSS vector (AV:N/AC:L/PR:N/UI:N), an unauthenticated remote attacker can trigger it directly over the network with no privileges or user interaction required. Successful exploitation yields remote code execution, with the critical 9.8 score reflecting complete impact on confidentiality, integrity, and availability on the compromised host. All Windows systems whose Event Logging Service builds fall within Microsoft's affected range are exposed, but the source data does not specify which Windows versions or KB updates are in scope. As of this analysis there is no known public proof-of-concept, the CVE is not in CISA KEV, and EPSS assigns a ~1.0% probability of exploitation within 30 days (61st percentile), indicating limited but nonzero near-term risk.
What to do: Check Microsoft's advisory for this CVE to identify affected Windows builds and apply the corresponding security update as the primary fix; no workaround is specified in the source data. Until patched, reduce exposure of internet-facing and high-value servers by restricting unauthenticated network access to their remote event-log endpoints (e.g., firewalling RPC reachability), and monitor CISA KEV and PoC trackers, as exploitation risk typically rises once patches are widely deployed.
| Microsoft Windows (Event Logging Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122, CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.