CVE-2026-69907
massLocal Privilege Elevation Flaw in Microsoft Windows Enterprise App Management
CVE-2026-69907 is a local privilege elevation vulnerability in Microsoft's Windows Enterprise App Management component, caused by improper handling of insufficient permissions or privileges (CWE-280). An attacker who already has limited local user rights on a vulnerable Windows machine can trigger the flaw locally, with no user interaction and low attack complexity required (CVSS: AV:L/PR:L/UI:N/AC:L). Successful exploitation grants elevated privileges with high impact on confidentiality, integrity, and availability, effectively giving the attacker administrative-level control over the host. Affected organizations are those running Windows builds containing the Enterprise App Management component, which is chiefly relevant to enterprise/MDM-managed endpoints; the specific affected build list was not included in the supplied data. As of now there are no reports of in-the-wild exploitation, no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at a modest 0.3%.
What to do: Patch via the Microsoft cumulative (Patch Tuesday) security update that addresses this CVE, checking Microsoft's advisory for the exact affected Windows builds in your estate, and prioritize Intune/MDM-managed Windows 10/11 endpoints where Enterprise App Management is enabled. Until patched, limit local interactive logon to trusted users, since exploitation requires an existing low-privileged local foothold. Monitor Microsoft's advisory for updates on affected versions or exploitation activity.
| Microsoft Windows Enterprise App Management | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-280
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.