Description
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

A heap‑based buffer overflow in the Windows Win32K graphics subsystem allows an attacker who already has local access to an account to write beyond the bounds of allocated memory. By exploiting this flaw, the attacker can elevate privileges on the affected machine, potentially gaining SYSTEM level rights and the ability to run arbitrary code or modify protected system files. The weakness is classified as CWE‑122, indicating an uncontrolled buffer overrun that compromises integrity and availability of the operating system for the local user.

Affected Systems

Microsoft Windows 11 24H2, 25H2, and 26H1, as well as Windows Server 2025 including Server Core installations, are all affected. The vulnerability applies to both arm64 (for the 24H2 and 25H2 builds) and x64 (for the 26H1 build). Users running earlier or later releases are not listed as impacted in the official CNA data.

Risk and Exploitability

The CVSS score of 7.8 places this issue in the high severity range, suggesting significant potential damage if exploited. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog, implying no widely known exploitation at the moment. However, because the flaw requires local authority to deliver crafted input to the Win32K subsystem, an attacker must be able to execute code or run a program locally with legitimate user credentials. In such an environment, exploitation could proceed with minimal detection if the malicious payload is crafted to avoid standard security defenses.

Generated by OpenCVE AI on September 8, 2026 at 20:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft Security Update for CVE-2026-69348, which is available for Windows 11 24H2, 25H2, 26H1 and Windows Server 2025.
  • If immediate patch deployment is not feasible, lock down local user accounts to the least privilege required for business functions and monitor for any anomalous elevation attempts.
  • Maintain a strict update cadence and keep the operating system fully patched to protect against future Win32K related vulnerabilities.

Generated by OpenCVE AI on September 8, 2026 at 20:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
Title Windows Win32k Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:35:10.413Z

Reserved: 2026-08-03T20:52:08.512Z

Link: CVE-2026-69348

cve-icon Vulnrichment

Updated: 2026-09-08T18:59:07.133Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:18:53.823

Modified: 2026-09-17T18:04:23.813

Link: CVE-2026-69348

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:01:41Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow