Integer overflow in Microsoft Windows and Windows Server - CVE-2026-69846
Published: September 8, 2026
Vulnerability details
The vulnerability allows a local privileged user to elevate privileges.
The vulnerability exists due to integer overflow or wraparound in Windows Secure Kernel Mode when processing a specially crafted Code Integrity policy. A local privileged user can submit a specially crafted Code Integrity policy to elevate privileges.
Successful exploitation can provide Virtual Trust Level 1 (VTL1) privileges and allow code execution in VTL1. Exploitation requires pre-existing kernel-level access.
Affected software
Windows Server
How to mitigate CVE-2026-69846
Windows Server - addressed in versions 2016 10.0.14393.9512, 2019 10.0.17763.9245, 2022 10.0.20348.5622, 2025 10.0.26100.33438