ZeroHour

CVE-2026-69625

mass

Heap-Based Buffer Overflow in Windows Connected User Experiences and Telemetry (EoP)

CVSS 3.1
8.0 high
EPSS
<1%p52
Published
()
Modified
AI analysis

CVE-2026-69625 is a heap-based buffer overflow (CWE-122) in the Windows Connected User Experiences and Telemetry component. According to Microsoft's CVSS vector (AV:N/AC:L/PR:L/UI:R), a low-privileged authorized attacker can trigger the flaw over a network, but user interaction is required, making this a remotely triggerable elevation-of-privilege issue rather than a pre-authentication remote code execution flaw. Successful exploitation allows privilege elevation with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.0, High). Any Windows installation carrying this component is potentially affected, though specific affected Windows versions are not listed in the available data. There is no evidence of active exploitation: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates only a 0.7% probability of exploitation within 30 days (52nd percentile).

What to do: Apply Microsoft's security update for CVE-2026-69625 as soon as it is published, checking Microsoft's Security Update Guide for the affected version ranges (not listed in the available data). Because exploitation requires low-privileged access and user interaction, the risk of unauthenticated remote compromise is low; prioritize patching multi-user and terminal-server systems where untrusted users interact. No alternative mitigation is documented, so treat patching as the primary remediation and watch for any added KEV listings or public PoCs.

Affected
Microsoft Windows (Connected User Experiences and Telemetry component)
Estimated exposure
mass≈1 billion+ Windows devices (component runs by default on Windows installs) — The Connected User Experiences and Telemetry service ships and runs by default on the roughly 1.4-billion-device Windows installed base, so installed-system exposure is in the billions, though exploitation requires low-privileged access…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.