CVE-2026-69841
massHeap-Based Buffer Overflow in Windows EFS Allows Local Privilege Escalation
A heap-based buffer overflow (CWE-122) in Microsoft's Windows Encrypting File System (EFS) can be triggered by an authorized attacker who is already able to execute low-privileged code locally on the target machine. Successful exploitation allows the attacker to elevate privileges to a higher local account, with high impact on confidentiality, integrity, and availability of the host. The flaw resides in the EFS component shipped with affected Windows editions; the available data does not enumerate specific Windows versions, so administrators should consult Microsoft's advisory for the applicable builds. As of this analysis there is no known in-the-wild exploitation, no public proof-of-concept, and the CVE is not in CISA's KEV, with a modest EPSS of 0.3% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69841, checking Microsoft's advisory for the affected Windows builds and corresponding updates. Prioritize multi-user systems, shared workstations, and hosts where untrusted users can run code, especially machines using EFS to protect sensitive files. No public PoC or in-the-wild exploitation is known, so a routine patch cycle is defensible, but keep EFS-enabled hosts on an accelerated schedule since local privilege escalations are frequently chained with other vulnerabilities.
| Microsoft Windows Encrypting File System (EFS), a component of Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.