ZeroHour

CVE-2026-70578

mass

Heap Buffer Overflow in Windows Credential Guard Enables Local Privilege Escalation

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-70578 is a heap-based buffer overflow (CWE-122) in Windows Credential Guard, the virtualization-based security component that isolates and protects credential material. To trigger it, an authorized attacker — meaning an attacker who has already obtained a low-privileged foothold on the local system — must exploit the flaw under high attack-complexity conditions, with no user interaction required. Successful exploitation lets the attacker elevate privileges locally on the affected machine, with high impact to confidentiality, integrity, and availability on that host per the CVSS scoring. Any Windows deployment with Credential Guard in use is in scope, but the exact affected Windows editions and version ranges are not specified in the available data and must be confirmed against Microsoft's advisory. Exploitation status: no public proof-of-concept, not listed in CISA KEV, and EPSS assigns only a 0.3% probability of exploitation in the next 30 days, so no active exploitation is currently known.

What to do: Monitor Microsoft's advisory and apply the Windows security update for CVE-2026-70578 as soon as it is released, prioritizing shared endpoints, jump hosts, and any system where multiple local users or untrusted code run. Because this is a local privilege escalation, treat it as a chaining risk: combine patching with least-privilege policies that limit which local accounts can run code on sensitive hosts. Verify where Credential Guard is enabled (e.g., via Device Guard/Credential Guard hardware readiness tooling or GPO/Intune reporting) to scope remediation, and confirm the exact affected version ranges in the official Microsoft advisory since they are not stated here.

Affected
Microsoft Windows Credential Guard (Windows client/server editions)
Estimated exposure
masson the order of hundreds of millions of Windows endpoints (Credential Guard ships with modern Windows Enterprise/Enterprise-managed SKUs and is enabled by… — Credential Guard is bundled with Windows 10/11 Enterprise-class SKUs and enabled by default on supported Windows 11 releases, so the potential install base is a large fraction of the roughly 1+ billion Windows devices in use, though only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Credential Guard allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.