6.4
CVE-2026-69874
- EPSS 0.33%
- Veröffentlicht 08.09.2026 17:16:49
- Zuletzt bearbeitet 16.09.2026 17:47:24
- Erkennungen
Windows ALPC Elevation of Privilege Vulnerability
Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 1809 HwPlatform x64 Version < 10.0.17763.9245
Microsoft ≫ Windows 10 1809 HwPlatform x86 Version < 10.0.17763.9245
Microsoft ≫ Windows 10 21h2 HwPlatform arm64 Version < 10.0.19044.7725
Microsoft ≫ Windows 10 21h2 HwPlatform x64 Version < 10.0.19044.7725
Microsoft ≫ Windows 10 21h2 HwPlatform x86 Version < 10.0.19044.7725
Microsoft ≫ Windows 10 22h2 HwPlatform arm64 Version < 10.0.19045.7725
Microsoft ≫ Windows 10 22h2 HwPlatform x64 Version < 10.0.19045.7725
Microsoft ≫ Windows 10 22h2 HwPlatform x86 Version < 10.0.19045.7725
Microsoft ≫ Windows 11 23h2 HwPlatform arm64 Version < 10.0.22631.7582
Microsoft ≫ Windows 11 23h2 HwPlatform x64 Version < 10.0.22631.7582
Microsoft ≫ Windows 11 24h2 HwPlatform arm64 Version < 10.0.26100.9445
Microsoft ≫ Windows 11 24h2 HwPlatform x64 Version < 10.0.26100.9445
Microsoft ≫ Windows 11 25h2 HwPlatform arm64 Version < 10.0.26200.9445
Microsoft ≫ Windows 11 25h2 HwPlatform x64 Version < 10.0.26200.9445
Microsoft ≫ Windows 11 26h1 HwPlatform arm64 Version < 10.0.28000.2954
Microsoft ≫ Windows 11 26h1 HwPlatform x64 Version < 10.0.28000.2954
Microsoft ≫ Windows Server 2019 HwPlatform x64 Version < 10.0.17763.9245
Microsoft ≫ Windows Server 2022 HwPlatform x64 Version < 10.0.20348.5622
Microsoft ≫ Windows Server 2025 HwPlatform x64 Version < 10.0.26100.33438
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.254 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.4 | 0.5 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| Microsoft | 8.2 | 1.5 | 6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-822 Untrusted Pointer Dereference
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69874