CVE-2026-69365: Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability
Published Sep 8, 2026
·Updated
Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability
Other sources
Out-of-bounds read in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
1 affected component
Microsoft Local Security Authority Server (LSA Server)
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
DescriptionSeverity
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need before exploiting this issue?
The attacker must already be authorized and have low-level privileges. Exploitation can be performed over the network, so local console access is not required.
2
What is the potential impact of successful exploitation?
Successful exploitation allows elevation of privilege and can affect confidentiality, integrity, and availability at a high level.
3
Does exploitation require user interaction?
Yes. The supplied vector indicates that user interaction is required, although the specific interaction needed is not described.