ZeroHour

CVE-2026-69844

mass

Out-of-Bounds Read in Windows Win32K Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69844 is an out-of-bounds read (CWE-125) in the Windows Win32K component, the kernel-side subsystem that handles window management, graphics, and input on Windows. A local attacker who is already authenticated with low-level privileges can trigger the flaw by performing operations that reach the vulnerable Win32K code path, causing the kernel to read memory outside the intended buffer. Successful exploitation allows the attacker to elevate privileges on the local machine, with the CVSS impact ratings (C:H/I:H/A:H) indicating the potential for full compromise of the affected system, typically meaning kernel-level or SYSTEM access. Any Windows installation containing the affected Win32K code is potentially affected; Microsoft's security advisory is the authoritative source for specific affected versions and updates. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS assigns only a 0.3% probability of exploitation within the next 30 days.

What to do: Apply the Microsoft security update for CVE-2026-69844 from the Microsoft advisory (Windows Update, WSUS, or Intune), checking the advisory for which Windows versions are affected. Given no known exploitation, no public PoC, and a low EPSS (0.3%), this can be handled in your regular Patch Tuesday cycle rather than as an emergency. On high-value servers, limiting interactive and remote-interactive (RDP) logon rights to trusted users reduces the local attack surface for privilege-escalation flaws like this one.

Affected
Microsoft Windows (Win32K kernel component)
Estimated exposure
mass≈1 billion Windows devices (Win32K ships with essentially all Windows client and server installations) — Win32K is present on effectively every Windows client and server SKU and Microsoft has stated Windows runs on over a billion active devices worldwide, so realistic exposure is at least hundreds of millions of endpoints and servers, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.

Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.