CVE-2026-69563
massHeap Overflow Local Privilege Escalation in Windows Program Compatibility Assistant Service
CVE-2026-69563 is a heap-based buffer overflow in the Windows Program Compatibility Assistant Service (PcaSvc), with associated time-of-check/time-of-use (TOCTOU) weakness indicating a race-condition element in how the service validates and uses resources. A local, authorized attacker with low privileges can trigger the flaw without user interaction, though the high attack-complexity score suggests reliable exploitation requires winning a timing race. Successful exploitation grants elevation of privileges on the local machine, with high impact on confidentiality, integrity, and availability at the system level. All Windows installations running the Program Compatibility Assistant Service are potentially affected; the available data does not specify exact affected or fixed version ranges, so defenders should consult Microsoft's advisory for coverage. As of now there is no known exploitation, no public proof-of-concept, no CISA KEV listing, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.
What to do: Apply the Microsoft security update addressing CVE-2026-69563 as part of your regular Windows patch cycle, prioritizing multi-user workstations, shared/VDI hosts, and endpoints where untrusted or low-privileged users routinely run code. Since no fixed version numbers are provided in this data, check Microsoft's advisory for the correct update per Windows edition and confirm the patch is installed via your patch-management reporting. No workarounds are documented; because this is a local privilege escalation, standard defense-in-depth (least privilege, restricting software installation) reduces practical exposure while you patch.
| Microsoft Windows (Program Compatibility Assistant Service, PcaSvc) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122, CWE-367
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.