CVE-2026-69544: Windows SMB Client Elevation of Privilege Vulnerability
Published Sep 8, 2026
·Updated
Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.
Other sources
Windows SMB Client Elevation of Privilege Vulnerability
— Microsoft
Affected Software
2 affected componentsFixes available
Microsoft Windows 11=26H1
10.0.28000.2954
Microsoft Windows 11=26H1
10.0.28000.2954
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2954Patch KB5124012
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:12 PM
Data Sourced
via MITRE·05:12 PM
DescriptionSeverity
Data Sourced
via NVD·06:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which systems are in scope for triage?
Microsoft Windows 11 systems are identified as affected. Prioritize devices where lower-privileged local users or accounts may be able to execute code.
2
What level of access does an attacker need?
Exploitation requires local access and low privileges. The available data does not indicate that unauthenticated or purely remote exploitation is possible.