Description
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a heap‑based buffer overflow in the Windows Error Reporting (WER) component that allows a local attacker with authorized access to overwrite critical memory structures. This overflow can corrupt internal data and result in the attacker running code with elevated privileges on the local system. According to the reported weakness the attack logic is grounded in CWE‑122, which concerns unchecked or inadequate bounds checking of heap data.

Affected Systems

Microsoft products affected by this vulnerability include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; as well as Windows Server 2016, 2019, 2022, and 2025 in both base and Server Core installations. These versions are listed as impacted in the CNA vendor/product data provided.

Risk and Exploitability

The CVSS score of 7.8 reflects a high severity for a local privilege escalation scenario. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. However, because the vulnerability requires local user interaction, an attacker who can log in or otherwise gain authorized access can use WER to trigger the heap overflow and elevate privileges, which poses a significant risk to system confidentiality and integrity if exploited.

Generated by OpenCVE AI on September 8, 2026 at 22:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update for CVE‑2026‑69433 through Windows Update, WSUS, or the Microsoft Update Catalog.
  • If the Windows Error Reporting function is not required, disable the WER service or restrict its permissions to prevent privileged execution.
  • Verify that local user accounts follow the principle of least privilege and consider removing unnecessary user rights that could facilitate exploitation.

Generated by OpenCVE AI on September 8, 2026 at 22:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
Title Windows Error Reporting Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 23h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T23:38:39.366Z

Reserved: 2026-08-03T20:59:32.784Z

Link: CVE-2026-69433

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:19:07.270

Modified: 2026-09-08T19:22:18.470

Link: CVE-2026-69433

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T22:15:17Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow