Junglewise Threat Intelligence

CVE-2026-69328: Microsoft Windows Storage untrusted search path privilege escalation

CVE-2026-69328 · Severity: high · CVSS 7.8 · Published 2026-09-08

Vendors: Microsoft.

Executive brief

Windows Storage is a core component of the Windows operating system responsible for managing data storage and file access. An authenticated attacker with local access to a Windows system can exploit an untrusted search path vulnerability in this component to gain elevated system privileges. This could enable an attacker to take full control of the affected computer and access sensitive data.

Technical details

The vulnerability exists in Windows Storage due to an untrusted search path flaw that allows privilege escalation. An authorized attacker with local access can exploit this issue to elevate their privileges from a standard user context to administrator or system level. The attack requires local access and existing user credentials but does not require network connectivity. An attacker successfully exploiting this vulnerability could achieve complete system compromise. Microsoft has released patches for this vulnerability via their regular security update process.

Affected products

  • Microsoft Windows Storage

Timeline

  • 2026-09-08: disclosed

References

Related threats