ZeroHour

CVE-2026-69906

mass

Heap Overflow in Microsoft Windows Secure Kernel Mode Allows Local Privilege Escalation

CVSS 3.1
8.2 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69906 is a heap-based buffer overflow (CWE-122) in Windows Secure Kernel Mode, the isolated, higher-trust kernel component that underpins Microsoft's Virtualization-Based Security (VBS). It is triggered locally by an already-authorized attacker who holds high privileges on the machine (CVSS PR:H), with no user interaction required. Successful exploitation allows the attacker to elevate privileges into the secure kernel's trust scope (CVSS scope-changed, S:C), with high impact to confidentiality, integrity, and availability, and potential undermining of VBS-protected assets such as credential isolation. Affected systems are Microsoft Windows releases that ship the Secure Kernel Mode component; the source data does not enumerate specific affected version ranges, and fixes shipped in Microsoft's September 2026 Patch Tuesday, whose coverage also highlighted related Snort detection rules. As of publication there is no known public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation within 30 days (25th percentile).

What to do: Apply the September 2026 Microsoft security updates across Windows endpoints and servers as soon as practical, prioritizing hosts where privileged accounts (administrators, services) log in locally. Check Microsoft's advisory for the exact affected version list and verify VBS/Secure Kernel status (e.g., System Information: 'Virtualization-based security' state) on high-value systems. Until patched, restrict interactive sessions for highly privileged accounts on shared or multi-user Windows systems, since exploitation requires an already-authorized local attacker.

Affected
Microsoft Windows (Secure Kernel Mode component / Virtualization-Based Security)
Estimated exposure
masshundreds of millions of Windows devices (Windows runs on >1 billion devices; affected subset is systems with the Secure Kernel/VBS component, commonly… — The global Windows install base exceeds one billion devices and the Secure Kernel is a standard component of modern Windows releases with VBS increasingly enabled by default, so the plausibly affected estate is on the order of hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs