Junglewise Threat Intelligence

CVE-2026-69496: Windows Compressed Folder heap buffer overflow

CVE-2026-69496 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Vendors: Microsoft.

Executive brief

Windows Compressed Folder is a built-in Windows utility that allows users to create and extract ZIP archives. A heap-based buffer overflow vulnerability could allow an attacker to execute arbitrary code on a target system by sending a specially crafted compressed file over the network, potentially compromising the entire system and accessing sensitive data.

Technical details

This is a heap-based buffer overflow vulnerability in Windows Compressed Folder that allows remote code execution. The vulnerability is triggered when processing a specially crafted compressed file, and an attacker can exploit it over the network without requiring authentication or user interaction beyond opening the malicious archive. The flaw allows arbitrary code execution with the privileges of the user who opens the file, potentially leading to full system compromise. A patch should be available from Microsoft through their regular security update channels.

Affected products

  • Microsoft Windows Compressed Folder

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory

References

Related threats