ZeroHour

CVE-2026-72967

mass

Heap-Based Buffer Overflow in Windows Network Connection Broker Allows Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-72967 is a heap-based buffer overflow (CWE-122) in the Windows Network Connection Broker, a built-in Windows service that manages network connectivity requests for applications. To trigger it, an authorized attacker must already be able to execute code on the local machine with low privileges, and no user interaction is required. Successful exploitation lets the attacker elevate their privileges locally, gaining high confidentiality, integrity, and availability impact on the target system. Any Windows installation where users can run untrusted code is affected, since the vulnerable component is a core Windows service; the data does not specify which Windows versions or builds are impacted. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and its low EPSS score (0.3%, 25th percentile) suggests exploitation activity is limited or nonexistent.

What to do: Check Microsoft's advisory and Windows Update for the designated security patch and apply it on an accelerated schedule, prioritizing multi-user systems, remote desktop hosts, and shared workstations where local accounts are common. Because exploitation requires an attacker to already run low-privileged code locally, limiting local logon rights and monitoring for suspicious process token changes can reduce interim risk. Verify affected builds in Microsoft's advisory, since the version ranges were not provided in this dataset.

Affected
Microsoft Windows (Network Connection Broker component)
Estimated exposure
masswell over 1 billion Windows installations (core Windows service) — The Network Connection Broker is a built-in Windows component present on effectively every Windows client machine, and Microsoft's installed base is commonly estimated at more than 1.4 billion devices.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.