Junglewise Threat Intelligence

CVE-2026-69785: Microsoft Windows Smart Card privilege escalation via untrusted search path

CVE-2026-69785 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Smart Card is a system component used for secure authentication and certificate management on Windows systems. An authorized attacker can exploit an untrusted search path vulnerability to escalate privileges on a local machine, potentially gaining full system control.

Technical details

This vulnerability exists in Windows Smart Card due to an untrusted search path that can be exploited during library/module loading. An attacker with local access can leverage this to achieve privilege escalation through DLL hijacking or similar path-based attack techniques. The vulnerability requires the attacker to be already authenticated or authorized on the system. The impact allows elevation from a standard or local user context to higher privileges, potentially reaching SYSTEM level. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows Smart Card

Timeline

  • 2026-09-08: disclosed

References