ZeroHour

CVE-2026-69501

mass

Untrusted Pointer Dereference Privilege Elevation in Windows Secure Kernel Mode

CVSS 3.1
7.0 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-69501 is an untrusted pointer dereference (CWE-822) in Microsoft Windows' Secure Kernel Mode, the isolated kernel component that supports Windows security features such as virtualization-based security. The flaw is triggered locally by an authorized attacker with low privileges and requires no user interaction, although the high attack complexity (AV:L/AC:H/PR:L) means exploitation depends on difficult-to-arrange conditions. Successful exploitation allows the attacker to elevate their privileges locally on the host, with high impact on confidentiality, integrity, and availability. All Windows systems running the affected Secure Kernel code are potentially affected, but the specific affected Windows versions were not provided in the available data. As of the September 2026 Patch Tuesday reporting, no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS assigns only a 0.2% probability of exploitation in the next 30 days (15th percentile).

What to do: Apply Microsoft's September 2026 Patch Tuesday security updates for Windows promptly and verify installed OS builds against the Microsoft advisory, since affected version details were not included here. As interim mitigation, restrict local/interactive sign-in on high-value hosts to trusted users. Monitor for public PoC releases or CISA KEV addition given the high-severity rating.

Affected
Microsoft Windows (Secure Kernel Mode)
Estimated exposure
mass≈1 billion+ Windows devices (global Windows installed base) — Windows runs on roughly 1.4 billion devices per public estimates, and a flaw in the Secure Kernel plausibly spans most supported Windows releases, though the specific affected version ranges were not provided.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2022, windows server 2025
Weakness
CWE-822
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs