CVE-2026-69685
massLocal Privilege Escalation via Heap-Based Buffer Overflow in Windows Kerberos
CVE-2026-69685 is a heap-based buffer overflow (CWE-122) in the Kerberos authentication component of Microsoft Windows. It is triggered locally by an authorized attacker who already holds a low-privileged account on the target system, and it requires no user interaction. Successful exploitation corrupts heap memory and grants the attacker elevated privileges on the host, with high impact to confidentiality, integrity, and availability per the CVSS 3.1 score of 7.8. Potentially any Windows system is affected through its built-in Kerberos component, though the available data does not enumerate specific affected editions or version ranges. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days (25th percentile).
What to do: Apply Microsoft's security update via Windows Update/WSUS as soon as your Windows version is covered by the advisory; specific KB numbers and build ranges are not included in the available data, so verify against Microsoft's release notes. Prioritize shared, multi-user, and domain-joined systems such as domain controllers and remote desktop hosts, since local privilege escalation is most valuable there; restricting local account creation is a limited compensating measure until patching is complete.
| Microsoft Windows Kerberos (built-in Windows authentication component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.