ZeroHour

CVE-2026-69822

mass

Local Privilege Elevation via Numeric Truncation in Microsoft Windows Kerberos

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69822 is a numeric truncation error (CWE-197) in the Windows Kerberos implementation, with the associated weakness data indicating the truncated value can lead to a heap-based buffer overflow (CWE-122). It is triggered when an authorized, low-privileged local user causes the flawed Kerberos handling on the machine — no user interaction is required, per the CVSS vector (AV:L/AC:L/PR:L/UI:N). An attacker who already has a foothold as a standard local user gains elevated privileges on the host, with CVSS impact rated high across confidentiality, integrity, and availability. Anyone running affected Windows releases is exposed, since Kerberos is a built-in Windows component; Microsoft (CNA [email protected]) is the authoritative source for the exact affected builds, which are not enumerated in the available data. There is currently no known exploitation: no public proof-of-concept, not listed in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation within 30 days.

What to do: Check Microsoft's Security Update Guide entry for CVE-2026-69822 to identify the affected Windows versions and apply the security update via Windows Update as soon as it is available, prioritizing Windows servers and multi-user workstations where standard users can log on locally. Until patched, limit interactive logon rights on sensitive Windows machines and monitor for anomalous local privilege escalation events. Near-term risk is low (no public PoC, not in CISA KEV, EPSS 0.3%), so standard patch-cycle urgency is appropriate.

Affected
Microsoft Windows Kerberos (built-in component of the Microsoft Windows operating system)
Estimated exposure
mass≈hundreds of millions of Windows endpoints (Kerberos ships as a core component of every modern Windows client and server) — The vulnerable Kerberos code is part of the Windows operating system itself, which is deployed on an estimated one billion-plus devices worldwide, so the plausible exposed population is of mass scale; the precise count depends on which…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122, CWE-197
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.