Junglewise Threat Intelligence

CVE-2026-69563: Microsoft Windows Program Compatibility Assistant Service heap buffer overflow

CVE-2026-69563 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

The Windows Program Compatibility Assistant Service contains a heap buffer overflow vulnerability that allows an authorized local user to execute arbitrary code with elevated privileges. This could enable a malicious insider or compromised account to take complete control of affected systems and access sensitive corporate data.

Technical details

A heap-based buffer overflow exists in the Windows Program Compatibility Assistant Service, allowing an attacker with local system access and appropriate authorization to trigger memory corruption. The vulnerability requires local network access and valid user credentials to exploit. A successful attack permits privilege escalation, enabling arbitrary code execution with SYSTEM-level permissions. Microsoft has released security updates to address this issue; affected organizations should apply patches immediately.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats