Junglewise Threat Intelligence

CVE-2026-69694: Microsoft Windows IP Address Management Service deserialization privilege escalation

CVE-2026-69694 · Severity: high · CVSS 7 · Published 2026-09-08

Vendors: Microsoft.

Executive brief

Windows IP Address Management (IPAM) Service is a Microsoft tool for managing and monitoring IP addresses across corporate networks. An authenticated attacker can exploit unsafe deserialization of untrusted data to elevate their privileges locally on the server, potentially gaining full control of the system.

Technical details

A deserialization vulnerability exists in the Windows IPAM Service where untrusted data is unsafely deserialized, allowing an authorized local attacker to execute arbitrary code with elevated privileges. The vulnerability requires prior authentication and local access to the affected system. An attacker with standard user privileges can trigger unsafe deserialization to escalate to SYSTEM or administrator level access. Microsoft has released a security update to address this issue.

Affected products

  • Microsoft Windows IP Address Management Service

Timeline

  • 2026-09-08: disclosed

References