ZeroHour

CVE-2026-70289

mass

Heap Buffer Overflow in Windows Win32 Kernel Subsystem Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-70289 is a heap-based buffer overflow (CWE-122) in the Win32 Kernel Subsystem of Microsoft Windows, the kernel component that services Win32/GUI-related system calls. An authorized local user could trigger the flaw by exercising the affected kernel code path, corrupting heap memory with no user interaction required (AV:L/PR:L/UI:N per the CVSS vector). Successful exploitation would let the attacker elevate from a limited local account to kernel-level privileges, with high impact on the confidentiality, integrity, and availability of the host. All Windows editions containing the vulnerable Win32 Kernel Subsystem code are plausibly exposed; exact affected version ranges are defined by Microsoft's advisory and were not provided in the source data. No exploitation is confirmed so far: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Install Microsoft's Windows security update addressing CVE-2026-70289 via Windows Update or your patch-management channel once released, and confirm against Microsoft's advisory which builds are affected. Until patched, prioritize systems where low-privileged or untrusted users can run code — shared workstations, terminal/RDS servers, and VDI hosts — and restrict local logon rights on sensitive machines.

Affected
Microsoft Windows (Win32 Kernel Subsystem)
Estimated exposure
mass≈1 billion+ Windows devices potentially affected (core kernel component present on essentially all Windows installs) — Windows runs on over a billion active devices (Microsoft has reported roughly 1.4 billion monthly active Windows 10/11 devices) and the Win32 Kernel Subsystem is a core component of those installations, so plausible exposure is on the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.