ZeroHour

CVE-2026-69528

mass

Missing-Authentication Local Privilege Escalation in Microsoft Windows Shell

CVSS 3.1
7.8 high
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-69528 is a missing-authentication flaw (CWE-306) in a critical function of the Microsoft Windows Shell, allowing an attacker with a low-privileged local account to interact with the function without proper authentication checks. The flaw is triggered locally by an authorized user or malware running with standard privileges on an affected Windows system, with no user interaction required. Successful exploitation lets the attacker elevate privileges on the local machine, gaining high impact on confidentiality, integrity, and availability of the system. Any Windows installation whose Windows Shell component includes the affected function is exposed, making the practical affected population effectively the entire Windows installed base. As of now there is no public proof of concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.3% chance of exploitation within 30 days.

What to do: Apply the Microsoft security update that resolves CVE-2026-69528 as soon as it is available through Windows Update or your patch management pipeline, since this is a local privilege escalation that malware can chain onto initial access. Until patched, limit local execution of untrusted code on Windows endpoints and review which accounts hold interactive logon rights. Because the flaw requires an authorized local attacker, prioritize patching multi-user systems, terminal servers, and endpoints where users or malware frequently run with standard privileges.

Affected
Microsoft Windows Shell
Estimated exposure
mass≈1 billion+ Windows devices (Windows Shell ships on essentially every Windows desktop and server) — Windows Shell is a default component of Microsoft Windows, so the affected population scales with Microsoft's reported base of over a billion monthly active Windows devices, though the practical exposure is limited by the need for local…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authentication for critical function in Windows Shell allows an authorized attacker to elevate privileges locally.

Weakness
CWE-306
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.