ZeroHour

CVE-2026-69594

mass

Heap-Based Buffer Overflow in Microsoft Windows LSASS Allows Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p26
Published
()
Modified
AI analysis

CVE-2026-69594 is a heap-based buffer overflow in Microsoft's Local Security Authority Server (lsasrv), the Windows component that implements authentication and security-authority functionality; the associated integer-overflow weakness (CWE-190) suggests a miscalculated size computation leads to the heap overflow. An authorized local user can trigger the flaw by sending crafted data to the LSASS process. Successful exploitation lets the attacker elevate privileges locally, escaping the confines of their assigned low-privilege account on the machine. Any Windows system where a low-privileged user can sign in is potentially affected, which in practice spans nearly the entire Windows installed base. As of this analysis there is no public proof-of-concept, no entry in CISA's KEV catalog, and EPSS estimates only a 0.3% probability of exploitation within 30 days, indicating no known in-the-wild exploitation.

What to do: Apply Microsoft's security update for CVE-2026-69594 via Windows Update as soon as it is available, and check Microsoft's advisory to identify which Windows versions are affected since the source data does not enumerate them. In the interim, restrict interactive logon rights for untrusted users on shared, multi-user, or jump-host systems, because exploitation requires an authorized local account. Monitor LSASS-related process activity for anomalies, noting that no public PoC or known exploitation exists as of this writing.

Affected
Microsoft Windows (Local Security Authority Server, lsasrv)
Estimated exposure
mass≈1.4 billion+ Windows devices (lsasrv ships as a core component on every Windows installation) — lsasrv is a core authentication component present on essentially all Windows client and server installations, so exposure is effectively the full Windows installed base (~1.4 billion+ devices per public market-share estimates), though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122, CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.