Junglewise Threat Intelligence

CVE-2026-68845: Microsoft Windows Program Compatibility Assistant Service heap buffer overflow

CVE-2026-68845 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

The Windows Program Compatibility Assistant Service is a Windows system component that helps older applications run on newer versions of Windows. A heap-based buffer overflow vulnerability in this service allows an authorized local user to execute code with elevated privileges, potentially leading to full system compromise.

Technical details

A heap-based buffer overflow exists in the Windows Program Compatibility Assistant Service that allows an authenticated local attacker to trigger memory corruption. The vulnerability requires local access and user-level authentication to exploit. By sending a specially crafted request to the service, an attacker can overflow a heap buffer and gain code execution in the service's context, resulting in privilege escalation from a standard user account to SYSTEM or administrator privileges. Patches are available from Microsoft.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats