CVE-2026-69544
massHeap Buffer Overflow in Microsoft Windows SMB Client Enables Local Privilege Escalation
CVE-2026-69544 is a heap-based buffer overflow (CWE-122) in the Windows SMB Client, the built-in Windows component that handles outgoing SMB file-sharing traffic. The flaw can be triggered when the SMB Client processes crafted SMB traffic, and because the attack vector is local (AV:L) and requires no user interaction, an attacker who already has low-privileged code execution on a machine can invoke it directly. Successful exploitation lets the authorized attacker elevate privileges locally, with high impact on confidentiality, integrity, and availability (i.e., compromise at a higher privilege level such as SYSTEM/administrator). Any Windows system carrying the affected SMB Client component is in scope, which effectively means Windows desktops and servers across Microsoft's supported releases; specific affected builds are enumerated in Microsoft's advisory rather than this record. Exploitation status is currently quiet: there is no known public proof-of-concept, the issue is not in CISA KEV, and EPSS puts the 30-day exploitation probability at just 0.3% (25th percentile).
What to do: Apply Microsoft's security update through Windows Update as soon as it is published, and check the Microsoft advisory for the exact affected Windows builds in your fleet. As an interim mitigation, consider restricting outbound SMB (TCP 445) from workstations to trusted servers only, since triggering the flaw requires the SMB Client to process hostile SMB traffic. No public PoC or in-the-wild exploitation is known, so this can be handled in the normal patch cycle unless you host many untrusted local users on shared systems.
| Microsoft Windows (SMB Client component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.