ZeroHour

CVE-2026-69729

mass

Heap Buffer Overflow in Windows Credential Providers Allows Network RCE

CVSS 3.1
8.8 high
EPSS
<1%p56
Published
()
Modified
AI analysis

CVE-2026-69729 is a heap-based buffer overflow (CWE-122) in Windows Credential Providers, the Windows components involved in logon authentication. An authorized attacker — one holding a valid low-privileged account — can trigger the flaw remotely over the network with no user interaction, per the CVSS vector (AV:N/AC:L/PR:L/UI:N). Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability, consistent with the 8.8 High CVSS score. All Windows deployments containing the affected Credential Provider code are in scope; the available data does not enumerate specific version ranges, so defenders must consult Microsoft's security bulletin for the exact affected-product list. There is currently no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only about a 0.9% chance of exploitation in the next 30 days, so it is not yet known to be exploited in the wild.

What to do: Apply Microsoft's security update for CVE-2026-69729 as soon as it is released, checking the bulletin for which Windows versions and servicing branches are covered. Until patched, reduce exposure by restricting network access to systems that accept remote authentication paths (such as RDP and remote logon) from untrusted sources, since exploitation requires only a valid account and network reachability. Monitor Microsoft's advisory for updated affected-product lists and any change in exploitation status, and treat high-value authentication endpoints (domain controllers, jump hosts, internet-exposed RDP) as priority patching targets.

Affected
Microsoft Windows (Credential Providers)
Estimated exposure
mass≈1 billion+ Windows devices (Windows installed base exceeds 1 billion devices per Microsoft's public figures) — Credential Providers ship as part of Windows itself rather than as an optional add-on, so potential exposure roughly tracks the global Windows installed base, which Microsoft has publicly reported at over one billion active devices; the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.