ZeroHour

CVE-2026-70568

mass

Heap Overflow in Windows Defender Firewall Service Enables Local Privilege Escalation

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-70568 is a heap-based buffer overflow (CWE-122) in the Windows Defender Firewall Service, a component that ships as part of Microsoft Windows. A local attacker who already holds an authorized, low-privileged account on the system can trigger the overflow under specific conditions (the flaw carries high attack complexity), with no user interaction required. Successful exploitation allows the attacker to elevate privileges on the local machine, with high impact on confidentiality, integrity, and availability of the host. Because the service is a default Windows component, essentially all Windows installations are potentially affected, though the available data does not specify affected version ranges. No public proof-of-concept is known, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days, indicating no observed exploitation yet.

What to do: Deploy the Microsoft security update for CVE-2026-70568 as soon as it is available, prioritizing multi-user systems such as terminal/RDS servers and shared workstations where untrusted local users can sign in. Until patching, restrict interactive and remote-interactive logon rights on Windows hosts to trusted users and check Microsoft's advisory for confirmed affected version ranges. Monitor EPSS, the CISA KEV catalog, and vendor guidance for changes in exploitation risk.

Affected
Microsoft Windows (Windows Defender Firewall Service)
Estimated exposure
mass>1,000,000 Windows installations (service present by default on essentially every Windows desktop and server) — The Windows Defender Firewall Service ships by default with Windows, whose global install base is on the order of a billion devices, so potential exposure spans the entire Windows ecosystem rather than a discrete product fleet.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.