ZeroHour

CVE-2026-69768

mass

Unauthenticated Heap Overflow RCE in Windows RNDIS Networking Component

CVSS 3.1
9.8 critical
EPSS
<1%p58
Published
()
Modified
AI analysis

CVE-2026-69768 is a heap-based buffer overflow (CWE-122) in Microsoft's implementation of RNDIS (Remote Network Driver Interface Specification), the protocol Windows uses for USB-tethered and virtual network devices. Per the CVSS vector, an unauthenticated remote attacker with no user interaction and low attack complexity can send crafted network traffic that the RNDIS component mishandles, overflowing a heap buffer and executing arbitrary code. Successful exploitation gives the attacker full control of the affected system, with high impact to confidentiality, integrity, and availability. Any Windows system exposing the vulnerable RNDIS component is affected, though the practical attack surface depends on whether RNDIS-based network interfaces are present or reachable. As of now there is no known public proof of concept, no confirmed in-the-wild exploitation, and the issue is not on the CISA KEV list, though the 9.8 severity rating makes prompt patching advisable.

What to do: Apply the relevant Microsoft security update via Windows Update / WSUS as soon as the vendor's advisory and patch are available, since no workaround fully corrects a kernel networking flaw. Inventory systems that use RNDIS interfaces (USB tethering, RNDIS-based adapters, some embedded/virtualization setups) and prioritize patching any that are network-exposed; disable or remove unused RNDIS interfaces where practical. Monitor Microsoft's advisory for the definitive affected-version list and any detection guidance, and watch for spikes in EPSS or KEV listing that would signal active exploitation.

Affected
Microsoft Windows (RNDIS remote network driver interface component)
Estimated exposure
mass≈1 billion+ devices (RNDIS ships with Windows; Microsoft reports over 1.3 billion active Windows devices), with the remotely reachable subset likely far smaller — Estimated from Microsoft's publicly reported global Windows device base, since RNDIS components ship with Windows by default; realistically exposed systems are those with RNDIS network interfaces active or otherwise network-reachable,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.