CVE-2026-69534
massCommand Injection Privilege Escalation in Windows Program Compatibility Assistant Service
CVE-2026-69534 is a command injection flaw (CWE-77) in the Windows Program Compatibility Assistant Service in which special command-syntax elements in input handled by the service are not properly neutralized. An attacker who already holds an authorized, low-privilege foothold on a local machine triggers it by getting the service to process crafted input, with no remote network access or user interaction required beyond local execution. Successful exploitation elevates the attacker to the service's privileged context, yielding high impact to confidentiality, integrity, and availability of the affected host (CVSS 3.1: 7.8, AV:L/PR:L). Because the Program Compatibility Assistant ships by default with Windows, the flaw potentially affects a broad range of Windows installations, though the available disclosure data does not enumerate specific affected builds, so defenders should consult Microsoft's advisory for exact versions. There is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS places 30-day exploitation probability near the median at about 0.6%, so no in-the-wild exploitation is known at publication time.
What to do: Apply the Microsoft security update addressing CVE-2026-69534 as soon as it is available for your Windows builds, prioritizing hosts where untrusted or low-privilege users can execute code such as shared workstations, RDS/VDI sessions, kiosks, and developer endpoints. Until patched, restrict local execution rights where feasible and monitor the Program Compatibility Assistant Service (PcaSvc) for unexpected child processes or unusual activity. Check Microsoft's advisory for the exact affected builds and any workarounds, since the summary data here does not enumerate specific version ranges.
| Microsoft Windows Program Compatibility Assistant Service | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of special elements used in a command ('command injection') in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.