CVE-2026-69717
massUntrusted Pointer Dereference Privilege Escalation in Windows Group Policy
CVE-2026-69717 is an untrusted pointer dereference in the Windows Group Policy component, categorized by Microsoft's data with related weaknesses CWE-125 (out-of-bounds read), CWE-822 (untrusted pointer dereference), and CWE-843 (resource type confusion). Per the CVSS vector, a low-privileged, authorized attacker can trigger the flaw over a network with user interaction required, causing the component to dereference an attacker-influenced or mistyped pointer. Successful exploitation allows elevation of privileges on the targeted system, with high impact on confidentiality, integrity, and availability. Effectively any Windows system that processes Group Policy is potentially affected — particularly domain-joined and centrally managed machines — though the provided data does not specify which Windows version ranges are vulnerable. Exploitation is not currently observed: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS assigns a modest 0.7% probability of exploitation within the next 30 days (51st percentile).
What to do: Apply Microsoft's security update for CVE-2026-69717 across supported Windows systems as it becomes available, prioritizing servers, domain controllers, and domain-joined endpoints where privilege elevation is most impactful. Because the affected version ranges are not detailed here, verify exposure against Microsoft's official bulletin rather than assuming all builds are vulnerable. No workaround is documented in the provided data, so patching is the primary mitigation; in the interim, monitor for anomalous privilege changes and restrict untrusted low-privileged access to systems where Group Policy processing can be triggered over the network.
| Microsoft Windows (Group Policy component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-125, CWE-822, CWE-843
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.