Junglewise Threat Intelligence

CVE-2026-69373: Microsoft Windows Overlay Filter integer overflow privilege escalation

CVE-2026-69373 · Severity: medium · CVSS 6.7 · Published 2026-09-08

Technologies: Microsoft Windows Overlay Filter. Vendors: Microsoft.

Executive brief

Windows Overlay Filter is a kernel-level component that manages visual effects and display overlays in Windows. An integer overflow vulnerability allows an authorized attacker with local access to corrupt memory and execute arbitrary code with elevated privileges, potentially compromising the entire system.

Technical details

The vulnerability is an integer overflow or wraparound in the Windows Overlay Filter kernel driver that allows an authorized attacker to trigger memory corruption via a crafted input. The attack requires local system access and involves interaction with the driver's input handling routines. Successful exploitation permits privilege escalation from a low-privileged user context to kernel level, enabling complete system compromise. A security patch is expected from Microsoft; patch status should be confirmed via the Microsoft Security Update Guide.

Affected products

  • Microsoft Windows Overlay Filter <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats