ZeroHour

CVE-2026-69544

mass

Heap Buffer Overflow in Microsoft Windows SMB Client Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69544 is a heap-based buffer overflow (CWE-122) in the Windows SMB Client, the built-in Windows component that handles outgoing SMB file-sharing traffic. The flaw can be triggered when the SMB Client processes crafted SMB traffic, and because the attack vector is local (AV:L) and requires no user interaction, an attacker who already has low-privileged code execution on a machine can invoke it directly. Successful exploitation lets the authorized attacker elevate privileges locally, with high impact on confidentiality, integrity, and availability (i.e., compromise at a higher privilege level such as SYSTEM/administrator). Any Windows system carrying the affected SMB Client component is in scope, which effectively means Windows desktops and servers across Microsoft's supported releases; specific affected builds are enumerated in Microsoft's advisory rather than this record. Exploitation status is currently quiet: there is no known public proof-of-concept, the issue is not in CISA KEV, and EPSS puts the 30-day exploitation probability at just 0.3% (25th percentile).

What to do: Apply Microsoft's security update through Windows Update as soon as it is published, and check the Microsoft advisory for the exact affected Windows builds in your fleet. As an interim mitigation, consider restricting outbound SMB (TCP 445) from workstations to trusted servers only, since triggering the flaw requires the SMB Client to process hostile SMB traffic. No public PoC or in-the-wild exploitation is known, so this can be handled in the normal patch cycle unless you host many untrusted local users on shared systems.

Affected
Microsoft Windows (SMB Client component)
Estimated exposure
mass≈1 billion+ Windows installations (SMB Client ships with every Windows desktop and server) — The SMB Client is a core Windows component present on effectively all Windows systems, so exposure scales with the on-the-order-of-a-billion global Windows installed base, though actual exploitability requires a local low-privileged…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.