CVE-2026-69594

Summary

Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.

Affected Software

VendorProductVersion RangeStatus
MicrosoftWindows 11 Version 24H210.0.26100.0 < 10.0.26100.9445affected
MicrosoftWindows 11 Version 25H210.0.26200.0 < 10.0.26200.9445affected
MicrosoftWindows 11 version 26H110.0.28000.0 < 10.0.28000.2954affected
MicrosoftWindows Server 202510.0.26100.0 < 10.0.26100.33438affected
MicrosoftWindows Server 2025 (Server Core installation)10.0.26100.0 < 10.0.26100.33438affected

Weaknesses

  • CWE-122: CWE-122: Heap-based Buffer Overflow
  • CWE-190: CWE-190: Integer Overflow or Wraparound

References