ZeroHour

CVE-2026-69564

mass

Heap buffer overflow in Windows OCSP enables local privilege escalation

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69564 is a heap-based buffer overflow (CWE-122) in the Windows Online Certificate Status Protocol (OCSP) component, with Microsoft ([email protected]) as the assigned CVE Numbering Authority and a CVSS 3.1 base score of 7.0 (high). It is exploited locally by an authorized (authenticated) attacker, with high attack complexity and no user interaction required. Successful exploitation elevates the attacker's privileges on the local machine, with high impact on confidentiality, integrity, and availability, though the vulnerability scope is unchanged (impact is limited to the affected host). The source data identifies the affected product only as the Windows OCSP component and does not specify which Windows versions or builds are vulnerable. As of this writing there is no public proof of concept, the flaw is not in the CISA KEV catalog, and EPSS estimates only about a 0.3% probability of exploitation within 30 days, indicating no known exploitation.

What to do: Apply Microsoft's security update for this CVE once Microsoft publishes the affected-build list, since no version ranges are present in the current data; in the interim, restrict local logon rights on hosts running OCSP/Online Responder functionality to trusted accounts and monitor those hosts for anomalous activity. Given EPSS of ~0.3%, no public PoC, and no KEV listing, treat this as a routine high-severity patching item rather than an emergency.

Affected
Microsoft Windows Online Certificate Status Protocol (OCSP)
Estimated exposure
masson the order of 1 billion Windows devices (Windows has roughly 1.4B monthly active devices) — Estimated from Microsoft's publicly reported ~1.4 billion monthly active Windows device base, assuming the OCSP component ships across Windows editions; actual reach could be narrower if only the server-side Online Responder (AD CS) role…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Online Certificate Status Protocol (OCSP) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.