Junglewise Threat Intelligence

CVE-2026-69277: Microsoft Local Security Authority Server stack-based buffer overflow

CVE-2026-69277 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Microsoft's Local Security Authority Server (lsasrv) is a core Windows system component responsible for authentication and access control. A stack-based buffer overflow vulnerability allows an authenticated attacker with local system access to gain elevated privileges, potentially compromising the entire system and enabling lateral movement to other systems on the network.

Technical details

A stack-based buffer overflow exists in the Local Security Authority Server (lsasrv.dll) component, allowing an authorized local attacker to write malicious code or data beyond buffer boundaries. The vulnerability requires local access and existing authentication credentials to trigger. Successful exploitation enables arbitrary code execution with SYSTEM privileges, effectively elevating an authenticated user's privileges from standard user to full system-level access. A patch is available from Microsoft Security Updates.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats