ZeroHour

CVE-2026-83996

mass

Heap Buffer Overflow in Windows Error Reporting Enables Local Privilege Escalation

CVSS 3.1
8.8 high
EPSS
<1%p13
Published
()
Modified
AI analysis

CVE-2026-83996 is a heap-based buffer overflow (CWE-122) in the Windows Error Reporting (WER) component of Microsoft Windows. A local attacker with only low-privilege authorized access can trigger the overflow when WER processes crafted error-reporting data, and the flaw requires no user interaction; the CVSS 'scope changed' metric indicates successful exploitation escapes the WER component's normal security context. An attacker who exploits it gains elevated privileges on the host with high confidentiality, integrity, and availability impact (CVSS 3.1 score 8.8), effectively administrator-level control that can be used to complete a compromise chain started by malware or another flaw. Anyone running the affected versions is exposed: Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2 through 26H1), and Windows Server 2012, 2016, 2019, and 2022, where WER is a default OS component. The flaw was addressed in Microsoft's September 2026 Patch Tuesday release, which fixed 973 vulnerabilities overall; no public proof-of-concept is known and the CVE is not listed in CISA KEV, and while that Patch Tuesday included two exploited zero-days, public exploitation of this specific CVE is not confirmed in the available data (EPSS is just 0.2%, percentile 14).

What to do: Apply the September 2026 Windows cumulative security update (Patch Tuesday) on all listed Windows 10, Windows 11, and Windows Server versions, and prioritize multi-user or exposed-attack-surface hosts such as RDS/terminal servers, VDI, shared workstations, and kiosks, since exploitation requires only low-privilege local access with no user interaction. No public workaround or exploit is known; confirm remediation by verifying the installed build is at the September 2026 update level (e.g., via winver or update history) and check Microsoft's advisory for the exact KBs per Windows version.

Affected
Microsoft Windows 101607, 1809, 21H2, 22H2 (all editions/builds prior to the September 2026 security update)
Microsoft Windows 1123H2, 24H2, 25H2, 26H1 (all builds prior to the September 2026 security update)
Microsoft Windows Server2012, 2016, 2019, 2022 (all builds prior to the September 2026 security update)
Estimated exposure
mass≈ 1 billion+ Windows devices and millions of Windows Server systems (WER is a default component on every listed version) — Windows Error Reporting ships by default in every affected Windows 10/11 and Windows Server release, so the exposed population is essentially the entire installed base of those versions, on the order of a billion-plus endpoints based on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities and 2 Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.

GBHackers · 6d agoAdvisory in the wildCVE-2026-85880CVE-2026-85877CVE-2026-85875+27 CVEs