ZeroHour

CVE-2026-69496

mass

Heap Buffer Overflow RCE in Windows Compressed Folder (CVSS 9.8)

CVSS 3.1
9.8 critical
EPSS
<1%p61
Published
()
Modified
AI analysis

CVE-2026-69496 is a heap-based buffer overflow (CWE-122) in the Windows Compressed Folder feature, the built-in Windows component that handles compressed archives. According to the CVSS vector, it is reachable over a network by an unauthorized attacker with no privileges and no user interaction, meaning an attacker can potentially trigger the flaw by sending crafted data to affected code without credentials. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability. Any Windows system that includes the Compressed Folder feature is affected; Microsoft has not specified the exact vulnerable version ranges in the provided data. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 1.0% probability of exploitation in the next 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69496 as soon as it is released via Windows Update, prioritizing internet-facing and shared systems, and check Microsoft's advisory for the exact affected version ranges since none were provided here. Until patched, review whether any systems expose archive-parsing functionality to untrusted network input and monitor for emerging PoCs given the critical network-RCE score. With no public exploit and a low EPSS (1.0%), immediate risk appears limited, but the AV:N/PR:N/UI:N vector makes prompt patching prudent.

Affected
Microsoft Windows (Compressed Folder feature)
Estimated exposure
masspotentially hundreds of millions to over 1 billion Windows installations (Compressed Folder ships by default with Windows) — The Compressed Folder component is included by default in Windows, which runs on well over a billion devices worldwide, so the potential affected population is effectively the entire Windows installed base until Microsoft's advisory…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.