Description
Heap-based buffer overflow in Microsoft Account allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a heap‑based buffer overflow in the Microsoft Account component that lets an authorized local user gain higher privileges on the affected system. This flaw aligns with CWE‑122, which can lead to local privilege escalation when the overflow is triggered. The exploit could allow the attacker to execute code with elevated rights, potentially compromising system integrity and confidentiality.

Affected Systems

Microsoft Windows 11 Version 24H2 and 25H2, as well as Windows Server 2025 (including Server Core installations), are affected. The flaw is present in the Microsoft Account service on these platforms, and the patch applies to the stated versions.

Risk and Exploitability

The CVSS score of 7.8 indicates a high risk level for local privilege escalation. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be local, requiring the attacker to have an authorized Microsoft Account session. Once the overflow is triggered, the attacker can gain elevated privileges on the machine. The lack of a publicly available exploit reduces immediate risk, but the severity suggests that administrative mitigation should be prioritized.

Generated by OpenCVE AI on September 8, 2026 at 19:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the security update for Windows 11 24H2, Windows 11 25H2, and Windows Server 2025 from Microsoft’s update guide.
  • If the update cannot be applied immediately, disable the Microsoft Account service or features to prevent the overflow until a patch is available.
  • Enforce least‑privilege local account policies and restrict Microsoft Account usage to trusted users only.

Generated by OpenCVE AI on September 8, 2026 at 19:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows Server 2025 (server Core Installation)

Thu, 10 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Account allows an authorized attacker to elevate privileges locally.
Title Microsoft Account Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:34:36.532Z

Reserved: 2026-07-31T16:47:02.144Z

Link: CVE-2026-68850

cve-icon Vulnrichment

Updated: 2026-09-09T09:58:54.749Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:33.747

Modified: 2026-09-09T10:17:40.070

Link: CVE-2026-68850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:03:49Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow