ZeroHour

CVE-2026-69785

mass

Untrusted Search Path Privilege Elevation in Windows Smart Card

CVSS 3.1
7.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-69785 is an untrusted search path vulnerability (CWE-426) in the Windows Smart Card component, meaning the component can load code from a location an attacker controls rather than its intended trusted location. An attacker who already has authorized low-privileged access to a local machine can place malicious code where the Smart Card component will find and load it, triggering the flaw without user interaction. Successfully exploiting it elevates the attacker's privileges on that machine, with high impact on confidentiality, integrity, and availability. Any Windows system containing the affected Smart Card component is potentially exposed, though exploitation requires a local foothold such as a standard user account or already-running malware. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.

What to do: Install the Windows security update addressing CVE-2026-69785 through Windows Update as part of your normal patch cycle, prioritizing shared and multi-user systems such as RDS/terminal servers, kiosks, and workstations where standard users log on locally. Because no public exploit is known, there is no urgent emergency action, but verify that the patch is applied across your Windows estate and restrict untrusted local logon on high-value hosts as interim mitigation. Confirm remediation against the version ranges listed in Microsoft's advisory, since the affected builds are not enumerated in the summary data.

Affected
Microsoft Windows (Smart Card component)
Estimated exposure
mass≈1 billion+ Windows installations carry the affected component, though exploitation requires local access — The Windows Smart Card component ships as part of the Windows operating system, whose installed base is on the order of a billion-plus devices, but the local-only attack vector means practical exposure depends on where untrusted users or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges locally.

Weakness
CWE-426
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.