Description
Heap-based buffer overflow in Windows Camera Frame Server Monitor allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local privilege escalation via heap overflow
Action: Patch Immediately
AI Analysis

Impact

The Windows Camera Frame Server Monitor contains a heap-based buffer overflow that permits an authorized local attacker to gain higher privileges by corrupting heap memory. The weakness, identified as CWE-122, arises in the way the service processes camera frame data and could allow an attacker to execute arbitrary code with elevated rights, thereby compromising system integrity.

Affected Systems

Affected vendors and products include Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025 and its Server Core installation. The vulnerability spans the specified OS releases and any system deploying the Camera Frame Server Monitor service on these platforms.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity local privilege escalation vulnerability, though the EPSS score is currently not available and the issue is not listed in CISA’s KEV catalog. The attack vector is local, requiring the attacker to have authorized access to the target machine and to trigger the heap overflow, likely through crafted camera data or similar interactions with the vulnerable service.

Generated by OpenCVE AI on September 8, 2026 at 22:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update that addresses CVE-2026-69542
  • Discontinue use of the Windows Camera Frame Server Monitor in environments where camera data cannot be trusted
  • Enforce the principle of least privilege for local accounts interacting with camera services

Generated by OpenCVE AI on September 8, 2026 at 22:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Windows Camera Frame Server Monitor allows an authorized attacker to elevate privileges locally.
Title Windows Camera Frame Server Monitor Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:35:47.762Z

Reserved: 2026-08-03T21:12:04.477Z

Link: CVE-2026-69542

cve-icon Vulnrichment

Updated: 2026-09-09T09:57:02.624Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:22.617

Modified: 2026-09-24T18:59:09.833

Link: CVE-2026-69542

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:58:15Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow