CVE-2026-69630
massOut-of-Bounds Read in Microsoft Windows Win32K Allows Local Privilege Escalation
CVE-2026-69630 is an out-of-bounds read (CWE-125) in Windows Win32K, the kernel-mode component that handles windowing and graphics. It is triggered by an authorized attacker — an authenticated user with low privileges on the local machine — under specific memory conditions (high attack complexity), with no user interaction required. Successful exploitation elevates the attacker's privileges locally, with high impact on confidentiality, integrity and availability at the kernel level. Any Windows system that grants interactive logon to untrusted or semi-trusted users is affected, notably workstations, terminal/RDS and VDI hosts, and kiosk deployments. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days (17th percentile).
What to do: Install the Windows security update addressing CVE-2026-69630 via Windows Update, WSUS or your patch management tooling, prioritizing multi-user hosts (RDS/VDI), kiosks, and systems exposing RDP to untrusted networks. Given the local-attack requirement, high complexity, and absence of public PoCs or in-the-wild exploitation, standard patch cadence is acceptable. Restrict interactive logon rights and audit local account membership to shrink the pool of potential local attackers.
| Microsoft Windows (Win32K kernel component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.