ZeroHour

CVE-2026-70583

mass

Heap-Based Buffer Overflow in Windows Core Messaging Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-70583 is a heap-based buffer overflow (CWE-122) in the Windows Core Messaging component of Microsoft Windows. An attacker who already holds a low-privileged account on a target system can trigger the flaw locally, with no user interaction required, causing memory corruption in the messaging component. Successful exploitation elevates the attacker's privileges to higher integrity levels, yielding broad system access with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). Any Windows installation containing the affected Core Messaging code is potentially exposed, though the affected Windows version ranges are not specified in the available data. There is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days (28th percentile).

What to do: Apply Microsoft's security update for CVE-2026-70583 via Windows Update as soon as it is released, checking the MSRC advisory for the exact update applicable to each Windows version since ranges are not specified here. Until patched, prioritize multi-user and shared systems (application servers, terminal/RDS hosts, shared workstations) where local standard users can log on, and monitor MSRC and CISA KEV for new exploitation evidence given no PoC is currently public.

Affected
Microsoft Windows (Core Messaging component)
Estimated exposure
mass~1 billion+ Windows devices (global Windows installed base), narrowed to a subset once Microsoft publishes affected versions — Core Messaging is a core Windows OS component and Windows runs on well over a billion active devices worldwide, so the plausible affected population is on the order of hundreds of millions to a billion installations, pending Microsoft's…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.