ZeroHour

CVE-2026-69685

mass

Local Privilege Escalation via Heap-Based Buffer Overflow in Windows Kerberos

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69685 is a heap-based buffer overflow (CWE-122) in the Kerberos authentication component of Microsoft Windows. It is triggered locally by an authorized attacker who already holds a low-privileged account on the target system, and it requires no user interaction. Successful exploitation corrupts heap memory and grants the attacker elevated privileges on the host, with high impact to confidentiality, integrity, and availability per the CVSS 3.1 score of 7.8. Potentially any Windows system is affected through its built-in Kerberos component, though the available data does not enumerate specific affected editions or version ranges. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days (25th percentile).

What to do: Apply Microsoft's security update via Windows Update/WSUS as soon as your Windows version is covered by the advisory; specific KB numbers and build ranges are not included in the available data, so verify against Microsoft's release notes. Prioritize shared, multi-user, and domain-joined systems such as domain controllers and remote desktop hosts, since local privilege escalation is most valuable there; restricting local account creation is a limited compensating measure until patching is complete.

Affected
Microsoft Windows Kerberos (built-in Windows authentication component)
Estimated exposure
masshundreds of millions of Windows devices (Kerberos ships as a core component in every Windows client and server OS) — The Kerberos security support provider is present on essentially all Windows installations, whose installed base is commonly estimated at over a billion devices, making the potentially affected population effectively the entire Windows…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.