CVE-2026-69844
massOut-of-Bounds Read in Windows Win32K Enables Local Privilege Escalation
CVE-2026-69844 is an out-of-bounds read (CWE-125) in the Windows Win32K component, the kernel-side subsystem that handles window management, graphics, and input on Windows. A local attacker who is already authenticated with low-level privileges can trigger the flaw by performing operations that reach the vulnerable Win32K code path, causing the kernel to read memory outside the intended buffer. Successful exploitation allows the attacker to elevate privileges on the local machine, with the CVSS impact ratings (C:H/I:H/A:H) indicating the potential for full compromise of the affected system, typically meaning kernel-level or SYSTEM access. Any Windows installation containing the affected Win32K code is potentially affected; Microsoft's security advisory is the authoritative source for specific affected versions and updates. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS assigns only a 0.3% probability of exploitation within the next 30 days.
What to do: Apply the Microsoft security update for CVE-2026-69844 from the Microsoft advisory (Windows Update, WSUS, or Intune), checking the advisory for which Windows versions are affected. Given no known exploitation, no public PoC, and a low EPSS (0.3%), this can be handled in your regular Patch Tuesday cycle rather than as an emergency. On high-value servers, limiting interactive and remote-interactive (RDP) logon rights to trusted users reduces the local attack surface for privilege-escalation flaws like this one.
| Microsoft Windows (Win32K kernel component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.