ZeroHour

CVE-2026-69688

mass

Heap Overflow in Windows Encrypting File System (EFS) Allows Privilege Escalation

CVSS 3.1
7.1 high
EPSS
<1%p45
Published
()
Modified
AI analysis

CVE-2026-69688 is a heap-based buffer overflow (CWE-122) in the Windows Encrypting File System (EFS), identified and coordinated by Microsoft. A remote attacker who already holds valid low-privilege credentials on the target can trigger the flaw over the network, but exploitation requires user interaction and is rated high attack complexity, so reliable success conditions are narrow. A successful exploit elevates the attacker's privileges, with high impact to confidentiality, integrity, and availability on the affected system. Any Windows installation carrying the EFS component is in scope; the available data does not specify which Windows versions or SKUs are affected. There is no known public proof-of-concept, the flaw is not listed in CISA's KEV catalog, and EPSS assigns only a 0.6% probability of exploitation within 30 days, so no active exploitation is currently known.

What to do: Apply the Microsoft security update for CVE-2026-69688 via Windows Update or the Microsoft Update Catalog as soon as it is released for your Windows version (affected version ranges were not specified in the provided data). Until patched, prioritize hosts where EFS is enabled and where low-privilege users can authenticate over the network, and caution users against interacting with untrusted content since exploitation requires user interaction. With no public PoC and no KEV listing, standard patch-cadence handling is reasonable; no workaround is documented.

Affected
Microsoft Windows Encrypting File System (EFS) component
Estimated exposure
mass≈1 billion Windows installations include the EFS component (est.); practical exposure narrower, limited to hosts with EFS in use — EFS is a built-in Windows feature (notably Professional/Enterprise editions), so the vulnerable code ships with the roughly 1.4 billion active Windows devices Microsoft publicly reports; the CVE data provides no version ranges, and actual…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.