Junglewise Threat Intelligence

CVE-2026-69459: Microsoft Windows Power Dependency Coordinator heap-based buffer overflow

CVE-2026-69459 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Power Dependency Coordinator is a system component that manages power and dependency relationships for services and processes on Windows systems. A heap-based buffer overflow in this component allows authenticated local users to execute arbitrary code and elevate their privileges to administrative level, potentially compromising system security.

Technical details

This vulnerability is a heap-based buffer overflow in the Windows Power Dependency Coordinator component. The vulnerability can be exploited by an authorized/authenticated local attacker to trigger a buffer overflow condition, leading to arbitrary code execution with elevated privileges. The attack vector is local, requiring prior authentication or local system access. A patch has been published by Microsoft through their Security Update Guide.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats