Junglewise Threat Intelligence

CVE-2026-69534: Microsoft Windows Program Compatibility Assistant Service command injection

CVE-2026-69534 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

The Windows Program Compatibility Assistant Service, a system component responsible for detecting and mitigating compatibility issues with legacy applications, contains a command injection vulnerability. An authenticated local attacker can exploit this flaw to execute arbitrary commands with elevated privileges, potentially gaining full system control.

Technical details

The vulnerability is a command injection flaw in the Windows Program Compatibility Assistant Service that fails to properly neutralize special elements in user-supplied input before passing it to a command execution function. The attack requires local authentication and code execution privileges on the target system. An authorized attacker can craft malicious input to inject shell metacharacters and execute arbitrary commands in the security context of the service (typically SYSTEM). This enables local privilege escalation from an authenticated user to SYSTEM-level access. Microsoft has released patches to address this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats