Junglewise Threat Intelligence

CVE-2026-69731: Microsoft Windows HID class driver heap overflow

CVE-2026-69731 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A heap buffer overflow vulnerability exists in Windows HID (Human Interface Device) class driver, a core component that handles input devices like keyboards and mice. An authorized local user can exploit this flaw to execute code with elevated system privileges, potentially gaining full control of the computer.

Technical details

A heap-based buffer overflow vulnerability exists in the Windows HID class driver, a kernel-mode component responsible for processing human interface device input. The vulnerability allows an authorized local attacker to overflow a heap buffer by supplying malformed input to the HID driver, achieving arbitrary code execution in kernel context. Network access is not required; the attacker must have local logon privileges. Successful exploitation results in privilege escalation to SYSTEM level. Microsoft has released patches to address this vulnerability.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats