Heap Buffer Overflow in Windows Error Reporting Enables Local Privilege Escalation
AI analysis
CVE-2026-83996 is a heap-based buffer overflow (CWE-122) in the Windows Error Reporting (WER) component of Microsoft Windows. A local attacker with only low-privilege authorized access can trigger the overflow when WER processes crafted error-reporting data, and the flaw requires no user interaction; the CVSS 'scope changed' metric indicates successful exploitation escapes the WER component's normal security context. An attacker who exploits it gains elevated privileges on the host with high confidentiality, integrity, and availability impact (CVSS 3.1 score 8.8), effectively administrator-level control that can be used to complete a compromise chain started by malware or another flaw. Anyone running the affected versions is exposed: Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2 through 26H1), and Windows Server 2012, 2016, 2019, and 2022, where WER is a default OS component. The flaw was addressed in Microsoft's September 2026 Patch Tuesday release, which fixed 973 vulnerabilities overall; no public proof-of-concept is known and the CVE is not listed in CISA KEV, and while that Patch Tuesday included two exploited zero-days, public exploitation of this specific CVE is not confirmed in the available data (EPSS is just 0.2%, percentile 14).
What to do: Apply the September 2026 Windows cumulative security update (Patch Tuesday) on all listed Windows 10, Windows 11, and Windows Server versions, and prioritize multi-user or exposed-attack-surface hosts such as RDS/terminal servers, VDI, shared workstations, and kiosks, since exploitation requires only low-privilege local access with no user interaction. No public workaround or exploit is known; confirm remediation by verifying the installed build is at the September 2026 update level (e.g., via winver or update history) and check Microsoft's advisory for the exact KBs per Windows version.
Affected
| Microsoft Windows 10 | 1607, 1809, 21H2, 22H2 (all editions/builds prior to the September 2026 security update) |
| Microsoft Windows 11 | 23H2, 24H2, 25H2, 26H1 (all builds prior to the September 2026 security update) |
| Microsoft Windows Server | 2012, 2016, 2019, 2022 (all builds prior to the September 2026 security update) |
Estimated exposure
mass≈ 1 billion+ Windows devices and millions of Windows Server systems (WER is a default component on every listed version) — Windows Error Reporting ships by default in every affected Windows 10/11 and Windows Server release, so the exposed population is essentially the entire installed base of those versions, on the order of a billion-plus endpoints based on…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.