Junglewise Threat Intelligence

CVE-2026-69493: Microsoft Windows Event Logging Service out-of-bounds read

CVE-2026-69493 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Event Logging Service, a core Windows system component responsible for recording system and application events, contains an out-of-bounds read vulnerability that allows remote attackers to execute arbitrary code without authentication. This vulnerability could lead to complete system compromise, unauthorized access to sensitive event logs, and potential deployment of malware across enterprise environments.

Technical details

The vulnerability is an out-of-bounds read in the Windows Event Logging Service that can be triggered over the network without authentication. The flaw permits remote code execution due to improper bounds checking when processing event log data. An attacker on the network can craft malicious input to trigger the out-of-bounds read, leading to information disclosure and arbitrary code execution with the privileges of the Event Logging Service. The high CVSS score (9.8) reflects the network-accessible attack vector, lack of authentication requirements, and severe impact on confidentiality, integrity, and availability.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats