ZeroHour

CVE-2026-69689

mass

Out-of-bounds read in Microsoft Windows Win32K enables privilege elevation

CVSS 3.1
8.0 high
EPSS
<1%p53
Published
()
Modified
AI analysis

CVE-2026-69689 is an out-of-bounds read (CWE-125, with CWE-121 also referenced) in the Windows Win32K kernel component, assigned by Microsoft and rated 8.0 (High) on CVSS 3.1. Per the CVSS vector, a low-privileged, authorized attacker can trigger the flaw over a network with user interaction required, causing the kernel to read beyond allocated memory bounds. Successful exploitation yields elevation of privilege on the targeted Windows system, with high impact to confidentiality, integrity, and availability. Any Windows deployment running the Win32K component — effectively the broad Windows client and server installed base — is potentially affected, though the available data does not specify exact version ranges. There is no evidence of exploitation in the wild, no public proof-of-concept, and the flaw is not in CISA's KEV; EPSS assigns a 0.8% probability of exploitation within 30 days (53rd percentile).

What to do: Track Microsoft's advisory and Patch Tuesday release, then apply the Windows security update for affected builds as soon as version ranges are published, since this data does not list specific versions. Because exploitation requires a low-privileged user and user interaction, prioritize patching shared and multi-user systems such as RDS/VDI hosts and machines where untrusted users hold local accounts, and monitor EPSS/KEV for changes in exploit likelihood.

Affected
Microsoft Windows (Win32K component)
Estimated exposure
mass≈hundreds of millions to >1 billion Windows endpoints (Win32K is a core component shipped with all Windows client and server installs) — estimate — Win32K ships with essentially every Windows edition and Microsoft has publicly reported an active base of well over a billion Windows devices, so the plausibly affected population is on the order of hundreds of millions of systems, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-121, CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.