Junglewise Threat Intelligence

CVE-2026-72967: Microsoft Windows Network Connection Broker heap overflow

CVE-2026-72967 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Network Connection Broker is a system component responsible for managing network connections on Windows computers. A heap-based buffer overflow in this component allows an authenticated local attacker to execute arbitrary code with elevated system privileges, potentially gaining full control of the affected machine.

Technical details

A heap-based buffer overflow vulnerability exists in the Windows Network Connection Broker component due to insufficient bounds checking when processing network connection data. The vulnerability requires the attacker to already have local authentication credentials on the target system. Exploitation allows an authenticated local attacker to overflow a heap buffer and overwrite adjacent memory structures, leading to arbitrary code execution with elevated privileges. The attack vector is local and requires prior system access. Patches are available from Microsoft.

Affected products

  • Microsoft Windows Network Connection Broker <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References