CVE-2026-70583
massHeap-Based Buffer Overflow in Windows Core Messaging Enables Local Privilege Escalation
CVE-2026-70583 is a heap-based buffer overflow (CWE-122) in the Windows Core Messaging component of Microsoft Windows. An attacker who already holds a low-privileged account on a target system can trigger the flaw locally, with no user interaction required, causing memory corruption in the messaging component. Successful exploitation elevates the attacker's privileges to higher integrity levels, yielding broad system access with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). Any Windows installation containing the affected Core Messaging code is potentially exposed, though the affected Windows version ranges are not specified in the available data. There is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days (28th percentile).
What to do: Apply Microsoft's security update for CVE-2026-70583 via Windows Update as soon as it is released, checking the MSRC advisory for the exact update applicable to each Windows version since ranges are not specified here. Until patched, prioritize multi-user and shared systems (application servers, terminal/RDS hosts, shared workstations) where local standard users can log on, and monitor MSRC and CISA KEV for new exploitation evidence given no PoC is currently public.
| Microsoft Windows (Core Messaging component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.