Microsoft has released fixes for CVE-2026-69277: Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability, an Important-severity flaw in the Microsoft Local Security Authority Server process, lsasrv.

The issue is a CWE-121 stack-based buffer overflow. Microsoft’s description is precise: “Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.” An attacker who successfully exploits the vulnerability could gain SYSTEM privileges—the highest local privilege level on Windows systems.

That makes this a patching priority for administrators. It is not a remotely reachable, no-click flaw; the supplied CVSS vector describes a local attack with low attack complexity and low privileges required. But SYSTEM-level escalation is the sort of result that turns a foothold into full control of a device. In security terms, it is the difference between getting through the lobby door and acquiring the building master key.

CVE-2026-69277 at a glance​

FieldDetail
CVECVE-2026-69277
TitleMicrosoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability
SeverityImportant
CVSS base score7.8
CVSS temporal score6.8
CVSS vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
WeaknessCWE-121
Vulnerable componentMicrosoft Local Security Authority Server (lsasrv)
Exploitation assessmentExploitation More Likely
Publicly disclosedPublicly disclosed: No
ExploitedExploited: No
Customer actionCustomer action required: Yes

Microsoft’s official advisory says an attacker who successfully exploited CVE-2026-69277 could gain SYSTEM privileges. The advisory also classifies the bug as a stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) that permits an authorized attacker to elevate privileges locally.

Why the LSA flaw matters​

Local Security Authority is one of Windows’ most security-sensitive components. It handles core security-policy and authentication-related work, so an elevation-of-privilege vulnerability in lsasrv demands attention even when an attacker must already be authorized on a machine.

The supplied CVSS vector is:

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

In practical terms, it describes an attack that is:

  • Local (AV:L), rather than directly reachable across a network.
  • Low complexity (AC:L), according to Microsoft’s scoring.
  • Dependent on low existing privileges (PR:L).
  • Not dependent on user interaction (UI:N).
  • Capable of affecting confidentiality, integrity, and availability at a high level (C:H/I:H/A:H) after successful exploitation.

That combination is why this is not a “patch it someday” bulletin. A locally authorized attacker who reaches SYSTEM can alter protected settings, interact with sensitive processes, and undermine the security boundary that separates ordinary users and services from the operating system itself.

Windows versions and fixed builds​

The fixes are delivered through version-specific cumulative updates. The important operational detail is that the same KB can correspond to different fixed builds depending on the Windows release. Administrators should therefore validate the installed build, not merely assume that a similarly named Windows edition has received the correct package.

Windows 10 remediation​

  • For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows 10 Version 21H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19044.7725.
  • For Windows 10 Version 21H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
  • For Windows 10 Version 21H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
  • For Windows 10 Version 22H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19045.7725.
  • For Windows 10 Version 22H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
  • For Windows 10 Version 22H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.

Windows 11 remediation​

  • For Windows 11 Version 23H2 for ARM64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
  • For Windows 11 Version 23H2 for x64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
  • For Windows 11 Version 24H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
  • For Windows 11 Version 24H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
  • For Windows 11 Version 25H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
  • For Windows 11 Version 25H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
  • For Windows 11 Version 26H1 for ARM64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
  • For Windows 11 version 26H1 for x64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.

Windows Server remediation​

  • For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
  • For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
  • For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
  • For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
  • For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
  • For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
  • For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
  • For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.

A practical deployment checklist​

For IT teams, the sensible response is straightforward:

  1. Inventory affected Windows clients and servers, including Server Core deployments and ARM64 endpoints.
  2. Match each machine’s release and architecture to its specific KB and fixed build above.
  3. Deploy the applicable cumulative update through the organization’s normal patch-management workflow.
  4. Verify post-installation build numbers, particularly where one KB serves multiple Windows releases with different target builds.
  5. Prioritize systems where low-privilege users or services can execute local code, since the vulnerability requires local authorized access and can lead to SYSTEM-level privileges.

CVE-2026-69277 is a textbook reason to avoid treating “local” as synonymous with “low consequence.” Microsoft’s own assessment is Exploitation More Likely, and the end state of a successful attack is SYSTEM. Patch the applicable Windows 10, Windows 11, and Windows Server installations to their listed fixed builds.

 

References

  1. Official MSRC or vendor evidence api.msrc.microsoft.com
  2. Official MSRC or vendor evidence msrc.microsoft.com
  3. Official MSRC or vendor evidence api.msrc.microsoft.com