CVE-2026-69513
massHeap Buffer Overflow in Windows Error Reporting Enables Local Privilege Escalation
CVE-2026-69513 is a heap-based buffer overflow (CWE-122) in the Windows Error Reporting (WER) component of Microsoft Windows. A local, authorized user with low privileges can trigger the flaw without user interaction, overrunning a heap buffer during WER processing. Successful exploitation allows elevation of privileges on the local machine, giving the attacker high-impact access to the system's confidentiality, integrity, and availability. Because WER ships by default with Windows, essentially every Windows desktop and server installation is potentially in scope, although the source data does not specify affected version ranges. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS predicts only a 0.3% probability of exploitation within 30 days (25th percentile).
What to do: Check Microsoft's advisory for the affected Windows version ranges and apply the patch through your standard Windows Update/WSUS/Intune/SCCM channels, prioritizing shared workstations, terminal servers, and VDI hosts where untrusted or low-privileged users can log on interactively. Until patched, restrict interactive logon rights on sensitive systems to trusted users, since exploitation requires local low-privileged access. Given no known PoC or in-the-wild exploitation, routine patch cadence is likely acceptable, but re-check KEV/EPSS for movement.
| Microsoft Windows (Windows Error Reporting component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.