Integer Overflow in Windows Secure Kernel Mode Enables Local Privilege Escalation
AI analysis
CVE-2026-69846 is an integer overflow or wraparound flaw (CWE-190) in the Windows Secure Kernel Mode, the isolated kernel component that underpins Virtualization-Based Security features such as Credential Guard. It is triggered locally by an authorized attacker who already holds high privileges on the machine (per the CVSS PR:H vector), by causing a size or count computation to wrap around and corrupt secure kernel memory. Successful exploitation lets the attacker elevate privileges across a security boundary (CVSS Scope: Changed), potentially gaining code execution at a higher trust level and undermining VBS-based protections. All Windows builds listed for this CVE in Microsoft's September 2026 Patch Tuesday advisory are affected; the available data does not enumerate specific versions, so administrators should consult the advisory for exact ranges. There is currently no public proof-of-concept, no entry in CISA's KEV catalog, and only a modest 0.3% EPSS probability of exploitation within 30 days, so no in-the-wild exploitation is known.
What to do: Deploy the Windows security updates released in Microsoft's September 2026 Patch Tuesday, which addresses this CVE, prioritizing servers and shared workstations where administrative rights are widely held. Because exploitation requires existing local high privileges, tightening local administrator membership and monitoring for anomalous privileged-process behavior reduces risk until patching is complete. Check Microsoft's advisory for the precise affected version ranges, since they are not listed in the available data.
Affected
| Microsoft Windows (Secure Kernel Mode) | — |
Estimated exposure
masshundreds of millions of Windows devices — The Secure Kernel is a standard component of VBS-capable Windows releases and Microsoft has publicly cited on the order of 1.4 billion active Windows devices, so the plausibly exposed base is in the hundreds of millions of endpoints even…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.