ZeroHour

CVE-2026-69841

mass

Heap-Based Buffer Overflow in Windows EFS Allows Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

A heap-based buffer overflow (CWE-122) in Microsoft's Windows Encrypting File System (EFS) can be triggered by an authorized attacker who is already able to execute low-privileged code locally on the target machine. Successful exploitation allows the attacker to elevate privileges to a higher local account, with high impact on confidentiality, integrity, and availability of the host. The flaw resides in the EFS component shipped with affected Windows editions; the available data does not enumerate specific Windows versions, so administrators should consult Microsoft's advisory for the applicable builds. As of this analysis there is no known in-the-wild exploitation, no public proof-of-concept, and the CVE is not in CISA's KEV, with a modest EPSS of 0.3% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69841, checking Microsoft's advisory for the affected Windows builds and corresponding updates. Prioritize multi-user systems, shared workstations, and hosts where untrusted users can run code, especially machines using EFS to protect sensitive files. No public PoC or in-the-wild exploitation is known, so a routine patch cycle is defensible, but keep EFS-enabled hosts on an accelerated schedule since local privilege escalations are frequently chained with other vulnerabilities.

Affected
Microsoft Windows Encrypting File System (EFS), a component of Windows
Estimated exposure
massOrder of hundreds of millions of Windows installations (EFS ships with Windows Pro/Enterprise/Education and Windows Server) — EFS is built into Windows professional editions and Windows Server, whose combined installed base runs to hundreds of millions of devices, though the flaw is only exploitable by local low-privileged users rather than remotely.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.