Executive brief
Microsoft RPC Runtime is a core Windows system component that enables applications to communicate remotely over networks. This vulnerability allows an attacker to write data outside of intended memory boundaries, potentially leading to remote code execution on affected systems without requiring authentication. An exploit could compromise server and client systems across a network, leading to data breach, service disruption, or installation of malware.
Technical details
The vulnerability is an out-of-bounds write flaw in the RPC Runtime component that can be triggered over the network by an unauthenticated attacker. The attack vector is network-based with no authentication required, allowing an attacker to send specially crafted RPC requests that cause memory corruption. Successful exploitation enables remote code execution with the privileges of the affected process. Microsoft has released security updates to address this issue; systems should be patched immediately.
Affected products
- Microsoft Windows RPC Runtime Multiple Windows versions
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory: CVE-2026-69819 published