CVE-2026-69900
massUntrusted Pointer Dereference in Microsoft Windows Kernel Streaming WOW Thunk Driver
CVE-2026-69900 is an untrusted pointer dereference (CWE-822) in Microsoft's Kernel Streaming WOW Thunk Service Driver, an in-box Windows kernel component that handles 32-bit (WOW) thunking for kernel streaming requests. An attacker who already holds valid low-privilege credentials on a machine can trigger the flaw by driving the driver through a malformed call path, causing the kernel to dereference an attacker-influenced pointer. Successful exploitation yields local privilege elevation to kernel/SYSTEM level, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8, AV:L/AC:L/PR:L/UI:N). Windows releases shipping this driver are plausibly affected, but the source data does not specify exact affected version ranges, so consult Microsoft's advisory for build-level detail. There is currently no known exploitation: no public PoC exists, the flaw is not in CISA KEV, and EPSS assigns a 0.3% probability of exploitation within 30 days (23rd percentile).
What to do: Apply the Windows security update addressing CVE-2026-69900 via Windows Update and check Microsoft's advisory for the exact affected builds, since version ranges were not provided in this data. Until patched, restrict local code execution to trusted users on shared systems such as RDP/VDI hosts and multi-user workstations, as exploitation requires an authenticated local session. Monitor for addition to CISA KEV or a rise in EPSS as triage signals.
| Microsoft Windows Kernel Streaming WOW Thunk Service Driver (in-box Windows component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-822
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.