Windows SMB Client Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-69544Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Heap-based buffer overflow in the Windows SMB Client component allows an authorized user with local access to escalate privileges on Windows 11 version 26H1 systems (x64 and ARM64). The vulnerability requires user-level credentials and local or interactive access to exploit. Exploitation is assessed as less likely.
What this means
What could happen
An authorized user on a Windows 11 system could exploit a heap-based buffer overflow in the SMB client to gain higher-level privileges on that machine, potentially allowing them to access sensitive files, modify system settings, or interfere with processes running on that workstation.
Who's at risk
This affects Windows 11 workstations and desktops (both x64 and ARM64 systems) running version 26H1 that are used in utility IT environments. This is primarily an IT concern rather than OT control systems, but any Windows 11 systems supporting OT engineering workstations, HMI servers, or historian systems should be patched to prevent lateral movement into industrial networks.
How it could be exploited
An attacker with user-level access to a Windows 11 system could trigger a heap-based buffer overflow in the SMB client component, bypassing normal privilege restrictions and escalating to system-level access. This requires local access and valid user credentials on the target machine.
Prerequisites
- Valid user account credentials on the Windows 11 system
- Local or interactive access to the Windows 11 machine
- SMB client service enabled (default configuration)
Low complexity exploitRequires local access and user credentialsAffects workstation/desktop systems primarilyLow EPSS score (0.3%)
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/2
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXApply Microsoft's 2026-Sep security update to Windows 11 systems running version 26H1
HARDENINGPrioritize patching workstations that are used by multiple users or in shared environments where privilege escalation risk is higher
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/bf149915-11ee-4944-bff5-49d66ceb734dGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.