ZeroHour

CVE-2026-69846

mass

Integer Overflow in Windows Secure Kernel Mode Enables Local Privilege Escalation

CVSS 3.1
8.2 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69846 is an integer overflow or wraparound flaw (CWE-190) in the Windows Secure Kernel Mode, the isolated kernel component that underpins Virtualization-Based Security features such as Credential Guard. It is triggered locally by an authorized attacker who already holds high privileges on the machine (per the CVSS PR:H vector), by causing a size or count computation to wrap around and corrupt secure kernel memory. Successful exploitation lets the attacker elevate privileges across a security boundary (CVSS Scope: Changed), potentially gaining code execution at a higher trust level and undermining VBS-based protections. All Windows builds listed for this CVE in Microsoft's September 2026 Patch Tuesday advisory are affected; the available data does not enumerate specific versions, so administrators should consult the advisory for exact ranges. There is currently no public proof-of-concept, no entry in CISA's KEV catalog, and only a modest 0.3% EPSS probability of exploitation within 30 days, so no in-the-wild exploitation is known.

What to do: Deploy the Windows security updates released in Microsoft's September 2026 Patch Tuesday, which addresses this CVE, prioritizing servers and shared workstations where administrative rights are widely held. Because exploitation requires existing local high privileges, tightening local administrator membership and monitoring for anomalous privileged-process behavior reduces risk until patching is complete. Check Microsoft's advisory for the precise affected version ranges, since they are not listed in the available data.

Affected
Microsoft Windows (Secure Kernel Mode)
Estimated exposure
masshundreds of millions of Windows devices — The Secure Kernel is a standard component of VBS-capable Windows releases and Microsoft has publicly cited on the order of 1.4 billion active Windows devices, so the plausibly exposed base is in the hundreds of millions of endpoints even…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs