CVE-2026-69689
massOut-of-bounds read in Microsoft Windows Win32K enables privilege elevation
CVE-2026-69689 is an out-of-bounds read (CWE-125, with CWE-121 also referenced) in the Windows Win32K kernel component, assigned by Microsoft and rated 8.0 (High) on CVSS 3.1. Per the CVSS vector, a low-privileged, authorized attacker can trigger the flaw over a network with user interaction required, causing the kernel to read beyond allocated memory bounds. Successful exploitation yields elevation of privilege on the targeted Windows system, with high impact to confidentiality, integrity, and availability. Any Windows deployment running the Win32K component — effectively the broad Windows client and server installed base — is potentially affected, though the available data does not specify exact version ranges. There is no evidence of exploitation in the wild, no public proof-of-concept, and the flaw is not in CISA's KEV; EPSS assigns a 0.8% probability of exploitation within 30 days (53rd percentile).
What to do: Track Microsoft's advisory and Patch Tuesday release, then apply the Windows security update for affected builds as soon as version ranges are published, since this data does not list specific versions. Because exploitation requires a low-privileged user and user interaction, prioritize patching shared and multi-user systems such as RDS/VDI hosts and machines where untrusted users hold local accounts, and monitor EPSS/KEV for changes in exploit likelihood.
| Microsoft Windows (Win32K component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-121, CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.