ZeroHour

CVE-2026-69907

mass

Local Privilege Elevation Flaw in Microsoft Windows Enterprise App Management

CVSS 3.1
7.8 high
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-69907 is a local privilege elevation vulnerability in Microsoft's Windows Enterprise App Management component, caused by improper handling of insufficient permissions or privileges (CWE-280). An attacker who already has limited local user rights on a vulnerable Windows machine can trigger the flaw locally, with no user interaction and low attack complexity required (CVSS: AV:L/PR:L/UI:N/AC:L). Successful exploitation grants elevated privileges with high impact on confidentiality, integrity, and availability, effectively giving the attacker administrative-level control over the host. Affected organizations are those running Windows builds containing the Enterprise App Management component, which is chiefly relevant to enterprise/MDM-managed endpoints; the specific affected build list was not included in the supplied data. As of now there are no reports of in-the-wild exploitation, no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at a modest 0.3%.

What to do: Patch via the Microsoft cumulative (Patch Tuesday) security update that addresses this CVE, checking Microsoft's advisory for the exact affected Windows builds in your estate, and prioritize Intune/MDM-managed Windows 10/11 endpoints where Enterprise App Management is enabled. Until patched, limit local interactive logon to trusted users, since exploitation requires an existing low-privileged local foothold. Monitor Microsoft's advisory for updates on affected versions or exploitation activity.

Affected
Microsoft Windows Enterprise App Management
Estimated exposure
masspotentially 100M+ Windows endpoints (enterprise-managed Windows devices carrying the built-in EAM component) — Windows Enterprise App Management ships as a built-in component of current Windows client releases, and Windows' global installed base exceeds one billion devices with a very large enterprise/Intune-managed subset, though the exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally.

Weakness
CWE-280
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.