CVE-2026-69481: Windows Enterprise App Management Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Enterprise App Management allows an authorized attacker to elevate privileges over a network.
Other sources
Windows Enterprise App Management Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What level of access does an attacker need before exploiting this issue?
The attacker must already be authorized and have low-level privileges. Exploitation is network-based and also requires user interaction.
Which systems should be considered in scope?
The affected software list includes Microsoft Windows 10, Windows 11, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025.
What is the potential impact of successful exploitation?
A successful heap-based buffer overflow can allow the authorized attacker to elevate privileges. The supplied severity vector indicates high potential impact to confidentiality, integrity, and availability.