CVE-2026-69389
Windows Storage Management Provider Elevation of Privilege Vulnerability
highEPSS 0.3 %
Beschreibung
Metriken
Severity
high
83.71
kein öffentlicher PoC bekannt
7.8
Veröffentlicht
2026-09-08 07:00 UTC
CWE-122
Weakness-Klassen (CWE)
CWE-122Variant
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- New CVE Received2026-09-08 18:19 UTC· secure@microsoft.com
- Description: Heap-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.
- CVSS V3.1: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE: CWE-122
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/69xxx/CVE-2026-69389.json">CVE-2026-69389</a>
IDCVE-2026-69389