ZeroHour

CVE-2026-69563

mass

Heap Overflow Local Privilege Escalation in Windows Program Compatibility Assistant Service

CVSS 3.1
7.0 high
EPSS
<1%p9
Published
()
Modified
AI analysis

CVE-2026-69563 is a heap-based buffer overflow in the Windows Program Compatibility Assistant Service (PcaSvc), with associated time-of-check/time-of-use (TOCTOU) weakness indicating a race-condition element in how the service validates and uses resources. A local, authorized attacker with low privileges can trigger the flaw without user interaction, though the high attack-complexity score suggests reliable exploitation requires winning a timing race. Successful exploitation grants elevation of privileges on the local machine, with high impact on confidentiality, integrity, and availability at the system level. All Windows installations running the Program Compatibility Assistant Service are potentially affected; the available data does not specify exact affected or fixed version ranges, so defenders should consult Microsoft's advisory for coverage. As of now there is no known exploitation, no public proof-of-concept, no CISA KEV listing, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.

What to do: Apply the Microsoft security update addressing CVE-2026-69563 as part of your regular Windows patch cycle, prioritizing multi-user workstations, shared/VDI hosts, and endpoints where untrusted or low-privileged users routinely run code. Since no fixed version numbers are provided in this data, check Microsoft's advisory for the correct update per Windows edition and confirm the patch is installed via your patch-management reporting. No workarounds are documented; because this is a local privilege escalation, standard defense-in-depth (least privilege, restricting software installation) reduces practical exposure while you patch.

Affected
Microsoft Windows (Program Compatibility Assistant Service, PcaSvc)
Estimated exposure
mass≈hundreds of millions of Windows endpoints (service ships enabled by default on Windows client editions) — The Program Compatibility Assistant Service is installed and enabled by default on Windows client systems, whose global installed base is on the order of a billion devices, making the potentially affected population effectively the entire…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122, CWE-367
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.