ZeroHour

CVE-2026-69900

mass

Untrusted Pointer Dereference in Microsoft Windows Kernel Streaming WOW Thunk Driver

CVSS 3.1
7.8 high
EPSS
<1%p23
Published
()
Modified
AI analysis

CVE-2026-69900 is an untrusted pointer dereference (CWE-822) in Microsoft's Kernel Streaming WOW Thunk Service Driver, an in-box Windows kernel component that handles 32-bit (WOW) thunking for kernel streaming requests. An attacker who already holds valid low-privilege credentials on a machine can trigger the flaw by driving the driver through a malformed call path, causing the kernel to dereference an attacker-influenced pointer. Successful exploitation yields local privilege elevation to kernel/SYSTEM level, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8, AV:L/AC:L/PR:L/UI:N). Windows releases shipping this driver are plausibly affected, but the source data does not specify exact affected version ranges, so consult Microsoft's advisory for build-level detail. There is currently no known exploitation: no public PoC exists, the flaw is not in CISA KEV, and EPSS assigns a 0.3% probability of exploitation within 30 days (23rd percentile).

What to do: Apply the Windows security update addressing CVE-2026-69900 via Windows Update and check Microsoft's advisory for the exact affected builds, since version ranges were not provided in this data. Until patched, restrict local code execution to trusted users on shared systems such as RDP/VDI hosts and multi-user workstations, as exploitation requires an authenticated local session. Monitor for addition to CISA KEV or a rise in EPSS as triage signals.

Affected
Microsoft Windows Kernel Streaming WOW Thunk Service Driver (in-box Windows component)
Estimated exposure
mass≈1 billion+ Windows installations (in-box OS component; exploitation is local-authenticated only) — The driver ships in-box with supported Windows releases and Microsoft Windows' active installed base is on the order of 1.4 billion devices, though the flaw is only reachable by an authenticated local user rather than over the network.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-822
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.