ZeroHour

CVE-2026-69694

large

Insecure Deserialization Local Privilege Escalation in Microsoft Windows IPAM Service

CVSS 3.1
7.0 high
EPSS
2%p76
Published
()
Modified
AI analysis

CVE-2026-69694 is an insecure deserialization flaw (CWE-502) in the Windows IP Address Management (IPAM) Service, an optional server feature used to manage enterprise IP address space. The service deserializes untrusted data in a way that can be abused by an authorized, low-privileged local user; exploitation requires uncommon conditions (high attack complexity) but no user interaction. A successful attack elevates the local attacker's privileges on the host, with high impact on confidentiality, integrity, and availability of the server. Exposure is limited to Windows Server installations where the IPAM feature is enabled, and specific affected version ranges were not provided in the source data. Exploitation has not been observed: the flaw is not in CISA's KEV catalog, no public proof-of-concept is known, and EPSS assigns a moderate 1.7% (76th percentile) probability of exploitation within 30 days.

What to do: Prioritize applying Microsoft's security update for CVE-2026-69694 on any Windows Server hosts where the IPAM feature is enabled (verify via Server Manager or the Windows Server features inventory), since default servers without the role are not affected. Until patching, restrict interactive and remote local logon on IPAM servers to trusted administrators, and monitor these hosts for suspicious privileged activity given the moderate EPSS likelihood of exploitation.

Affected
Microsoft Windows Server — IP Address Management (IPAM) Service (optional feature; affects servers with the IPAM role/feature enab
Estimated exposure
large≈10,000–100,000 Windows Server instances with the optional IPAM feature enabled worldwide (estimate) — No public install-base counts or internet-scan data exist for the IPAM Server role, so the estimate assumes a small fraction of the very large Windows Server installed base runs this non-default, enterprise-focused feature (mostly in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-502
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.