ZeroHour

CVE-2026-69731

mass

Heap Overflow in Microsoft Windows HID Class Driver Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p23
Published
()
Modified
AI analysis

CVE-2026-69731 is a heap-based buffer overflow (CWE-122) in Microsoft's HID class driver, the component that processes Human Interface Device (keyboard, mouse, and similar input device) traffic. An attacker who already holds valid low-privilege credentials on the local machine can trigger the overflow through the HID driver without any user interaction, corrupting heap memory. Successful exploitation elevates the attacker's privileges locally, and the CVSS impact ratings (high for confidentiality, integrity, and availability) indicate full system compromise is possible. Any system running the affected Microsoft HID class driver is exposed; the affected version ranges are not specified in the available data, so administrators should check Microsoft's advisory for applicability. As of this analysis the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS puts the 30-day exploitation probability at just 0.3% (23rd percentile), so no exploitation is currently known.

What to do: Monitor Microsoft's advisory (CNA [email protected]) for the affected Windows version ranges and install the security update through Windows Update as soon as it is released. Until patched, limit local interactive and RDP logon to trusted users on sensitive systems, since exploitation requires an authorized local account. With no public PoC or in-the-wild exploitation known, standard patch cadence is reasonable for most estates, but prioritize multi-user workstations and terminal/RDS servers where unprivileged users log on.

Affected
Microsoft Windows HID class driver (HID class driver component; Windows inferred from the Microsoft CNA assignment)
Estimated exposure
mass>1,000,000 Windows installations (HID class driver ships on essentially all Windows devices) — Microsoft's HID class driver is a core Windows component present on virtually every Windows installation and Windows runs on well over a billion active devices, so plausible exposure is mass-scale, bounded by whichever Windows versions…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in HID class driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.