Description
Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

A heap‑based buffer overflow exists in the Windows Credential Providers component, permitting an attacker who can send crafted input over a network to execute arbitrary code with the privileges of the credential provider process. The flaw arises when malformed credential data is processed, overflowing a heap buffer and enabling control over the affected system. This vulnerability is a classic example of CWE‑122, resulting in complete loss of confidentiality, integrity, and availability for the compromised host.

Affected Systems

Microsoft Windows 11 versions 24H2, 25H2 and 26H1, and Windows Server 2025—including Server Core installations—are affected. The issue is present on ARM64 for the 24H2 and 25H2 releases and on x64 for 26H1, while the Server 2025 target is platform‑agnostic as listed.

Risk and Exploitability

The CVSS score of 8.8 reflects high severity. EPSS data is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. Nevertheless, the flaw is exploitable by an authorized user who can reach the Credential Provider over the network and supply malicious data. Successful exploitation would grant the attacker full control of the affected system. Given the high CVSS and the lack of a public exploit, the risk remains significant and warrants immediate mitigation.

Generated by OpenCVE AI on September 10, 2026 at 00:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Microsoft security update that addresses CVE‑2026‑69729 on all affected Windows 11 and Windows Server 2025 installations.
  • Limit exposure of systems to untrusted networks by enforcing network segmentation and ensuring that only trusted devices can access the Credential Provider services.
  • Monitor authentication and credential provider events for anomalous activity, and use audit logs to detect potential exploitation attempts.

Generated by OpenCVE AI on September 10, 2026 at 00:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to execute code over a network.
Title Windows Credential Providers Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:31:55.541Z

Reserved: 2026-08-03T21:35:55.264Z

Link: CVE-2026-69729

cve-icon Vulnrichment

Updated: 2026-09-10T14:08:50.503Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:45.010

Modified: 2026-09-22T20:05:59.300

Link: CVE-2026-69729

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:09:41Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow