CVE-2026-69494
massOut-of-Bounds Read RCE in Windows Event Logging Service
CVE-2026-69494 is an out-of-bounds read (CWE-125, also tagged CWE-122) in the Microsoft Windows Event Logging Service that Microsoft assigns to [email protected] and scores 8.8 (High) with a network attack vector, no privileges required, and user interaction required. By getting crafted input processed by the service, an unauthenticated attacker can cause the service to read beyond the bounds of allocated memory, which Microsoft rates as leading to remote code execution over the network. A successful attacker gains code execution on the target host, with the High-rated confidentiality, integrity, and availability impact reflected in the CVSS score. The flaw affects Windows systems running the Event Logging Service; the available data does not enumerate which specific Windows versions or builds are affected. Exploitation status: no public proof-of-concept is known, the CVE is not in CISA KEV, and EPSS puts 30-day exploitation probability at 0.8% (56th percentile).
What to do: Apply Microsoft's security update for CVE-2026-69494 as soon as it is available, prioritizing network-reachable hosts such as servers and remote-access systems, and check Microsoft's advisory for the precise list of affected Windows versions since none are enumerated here. With no public PoC, KEV listing, or observed exploitation, defenders have some lead time, but the network-exploitable vector and 8.8 severity warrant prompt patching. As interim hardening, limit untrusted network access to affected hosts and monitor Windows event log service activity for anomalies.
| Microsoft Windows Event Logging Service | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122, CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.