ZeroHour

CVE-2026-69790

mass

Heap Overflow in Windows Credential Providers Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69790 is a heap-based buffer overflow (CWE-122) in the Windows Credential Providers, the Windows component that handles authentication at logon and other credential prompts. It is triggered locally by an authorized attacker who already holds a low-privilege account on the target machine, with no user interaction required. Successful exploitation allows the attacker to elevate privileges locally, gaining high-impact control over confidentiality, integrity, and availability (typically SYSTEM-level access). All Windows systems are potentially affected because Credential Providers ship with the operating system, though the source data does not enumerate specific affected Windows versions. Exploitation status is quiet: there is no known in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69790 as soon as it is released, since the data does not list patched build numbers — check Microsoft's advisory for the specific affected Windows versions. Until patched, limit local interactive and Remote Desktop logon rights to trusted users, as exploitation requires an already-authorized local account. Monitor Microsoft's advisory for updated affected-product and patch information.

Affected
Microsoft Windows (Credential Providers component)
Estimated exposure
mass≈1 billion+ Windows devices (Credential Providers are a default Windows component) — Credential Providers ship with Windows by default on every installation, and Windows' active install base is estimated at over one billion devices, so any Windows endpoint where a low-privilege local user can authenticate is potentially in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.