Junglewise Threat Intelligence

CVE-2026-69564: Microsoft Windows OCSP heap buffer overflow

CVE-2026-69564 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows OCSP is a component responsible for validating digital certificates used in secure communications. A heap-based buffer overflow in this component allows a local attacker with existing system access to gain elevated privileges, potentially gaining full control over the affected computer.

Technical details

A heap-based buffer overflow exists in the Windows Online Certificate Status Protocol (OCSP) implementation. The vulnerability is triggered through improper buffer management in certificate validation processing, allowing a local authorized attacker to overwrite heap memory. The attack requires prior local system access and results in privilege escalation to a higher privilege level. A patch is available from Microsoft via the Security Update Guide.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats