CVE-2026-68850: Microsoft Account Elevation of Privilege Vulnerability
Published Sep 8, 2026
·Updated
Heap-based buffer overflow in Microsoft Account allows an authorized attacker to elevate privileges locally.
Other sources
Microsoft Account Elevation of Privilege Vulnerability
— Microsoft
Affected Software
11 affected componentsFixes available
Microsoft Windows 11=25H2
10.0.26200.9445
Microsoft Windows Server 2025<10.0.26100.33438
10.0.26100.33438
Microsoft Windows 11=24H2
10.0.26100.9445
Microsoft Windows 11=25H2
10.0.26200.9445
Microsoft Windows Server 2025<10.0.26100.33438
10.0.26100.33438
Microsoft Windows 11=24H2
10.0.26100.9445
Microsoft Windows 11 24h2<10.0.26100.9445
Microsoft Windows 11 24h2<10.0.26100.9445
Microsoft Windows 11 25h2<10.0.26200.9445
Microsoft Windows 11 25h2<10.0.26200.9445
Microsoft Windows Server 2025<10.0.26100.33438
Remediation
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:14 PM
Data Sourced
via MITRE·05:14 PM
DescriptionSeverity
Data Sourced
via NVD·06:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who can exploit this vulnerability?
An attacker must already be authorized on the affected system and have local access. The issue affects Microsoft Windows 11 and Microsoft Windows Server 2025.
2
What level of access is required for exploitation?
Exploitation requires low privileges and does not require user interaction. It is a local elevation-of-privilege issue, so it is not described as remotely exploitable from the provided data.
3
What impact could successful exploitation have?
Successful exploitation could allow an authorized local attacker to elevate privileges. The supplied severity vector indicates high confidentiality, integrity, and availability impact.