Junglewise Threat Intelligence

CVE-2026-69391: Windows Broker Infrastructure Service stack-based buffer overflow

CVE-2026-69391 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

The Windows Broker Infrastructure Service, a core component that manages inter-process communication in Windows, contains a stack-based buffer overflow vulnerability. An authorized local attacker can exploit this flaw to execute code with elevated privileges, potentially gaining complete system control.

Technical details

A stack-based buffer overflow exists in the Windows Broker Infrastructure Service, exploitable by an authenticated local attacker via a malicious local function call. Successful exploitation allows arbitrary code execution in the context of the service, leading to privilege escalation. A patch is available from Microsoft.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats