CVE-2026-69564
massHeap buffer overflow in Windows OCSP enables local privilege escalation
CVE-2026-69564 is a heap-based buffer overflow (CWE-122) in the Windows Online Certificate Status Protocol (OCSP) component, with Microsoft ([email protected]) as the assigned CVE Numbering Authority and a CVSS 3.1 base score of 7.0 (high). It is exploited locally by an authorized (authenticated) attacker, with high attack complexity and no user interaction required. Successful exploitation elevates the attacker's privileges on the local machine, with high impact on confidentiality, integrity, and availability, though the vulnerability scope is unchanged (impact is limited to the affected host). The source data identifies the affected product only as the Windows OCSP component and does not specify which Windows versions or builds are vulnerable. As of this writing there is no public proof of concept, the flaw is not in the CISA KEV catalog, and EPSS estimates only about a 0.3% probability of exploitation within 30 days, indicating no known exploitation.
What to do: Apply Microsoft's security update for this CVE once Microsoft publishes the affected-build list, since no version ranges are present in the current data; in the interim, restrict local logon rights on hosts running OCSP/Online Responder functionality to trusted accounts and monitor those hosts for anomalous activity. Given EPSS of ~0.3%, no public PoC, and no KEV listing, treat this as a routine high-severity patching item rather than an emergency.
| Microsoft Windows Online Certificate Status Protocol (OCSP) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Online Certificate Status Protocol (OCSP) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.