CVE-2026-69790
massHeap Overflow in Windows Credential Providers Enables Local Privilege Escalation
CVE-2026-69790 is a heap-based buffer overflow (CWE-122) in the Windows Credential Providers, the Windows component that handles authentication at logon and other credential prompts. It is triggered locally by an authorized attacker who already holds a low-privilege account on the target machine, with no user interaction required. Successful exploitation allows the attacker to elevate privileges locally, gaining high-impact control over confidentiality, integrity, and availability (typically SYSTEM-level access). All Windows systems are potentially affected because Credential Providers ship with the operating system, though the source data does not enumerate specific affected Windows versions. Exploitation status is quiet: there is no known in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69790 as soon as it is released, since the data does not list patched build numbers — check Microsoft's advisory for the specific affected Windows versions. Until patched, limit local interactive and Remote Desktop logon rights to trusted users, as exploitation requires an already-authorized local account. Monitor Microsoft's advisory for updated affected-product and patch information.
| Microsoft Windows (Credential Providers component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.