Junglewise Threat Intelligence

CVE-2026-70568: Microsoft Windows Defender Firewall Service heap overflow

CVE-2026-70568 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

Windows Defender Firewall Service is a core security component that manages network traffic filtering and protection on Windows systems. A heap-based buffer overflow vulnerability allows an authorized attacker with local access to escalate their privileges to system level, potentially compromising the entire computer and all data on it.

Technical details

A heap-based buffer overflow exists in the Windows Defender Firewall Service that can be triggered by an authorized local user. The vulnerability allows an attacker with authenticated local access to overflow a heap buffer in the firewall service, achieving code execution with elevated privileges. This is a local privilege escalation vulnerability requiring prior authentication and local code execution capability. Microsoft has issued patches to address this flaw. The CVSS base score is 7.0, reflecting the local-only attack vector but significant impact on system confidentiality and integrity.

Affected products

  • Microsoft Windows Defender Firewall Service <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References