Abstract illustration of connected devices separated by a protected security boundary.
Microsoft has published CVE-2026-69436, Windows State Repository Service Elevation of Privilege Vulnerability, rated Important. The issue is a CWE-122 heap-based buffer overflow: “Heap-based buffer overflow in Windows State Repository Service allows an authorized attacker to elevate privileges locally.”

Its CVSS base score is 7.8, with a CVSS temporal score of 6.8 and this vector:

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

The practical risk is local privilege escalation. An attacker must already be authorized on the affected machine, but Microsoft’s advisory states that a successful exploit could yield SYSTEM privileges—the level at which Windows security boundaries become considerably less comforting.

  • Publicly disclosed: No
  • Exploited: No
  • Customer action required: Yes
  • Microsoft’s exploitation assessment: Exploitation More Likely

What Microsoft says​

Microsoft’s advisory includes the following facts:

Windows Error Reporting Elevation of Privilege Vulnerability: Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
Windows State Repository Service Elevation of Privilege Vulnerability: Heap-based buffer overflow in Windows State Repository Service allows an authorized attacker to elevate privileges locally.
What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

For IT administrators, this is a patching priority rather than a wait-and-see item. A local attacker or a user-level foothold does not automatically equal full machine control—but an elevation-of-privilege flaw can be the rung that turns a limited compromise into a much more serious incident.

Affected Windows versions and fixed builds​

Install the applicable cumulative update and verify that the device reaches the corresponding fixed build.

Affected productRequired updateFixed build
Windows 10 Version 1809 for 32-bit Systems (x86)KB512287610.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsKB512287610.0.17763.9245
Windows 10 Version 21H2 for 32-bit Systems (x86)KB512287810.0.19044.7725
Windows 10 Version 21H2 for ARM64-based SystemsKB512287810.0.19044.7725
Windows 10 Version 21H2 for x64-based SystemsKB512287810.0.19044.7725
Windows 10 Version 22H2 for 32-bit Systems (x86)KB512287810.0.19045.7725
Windows 10 Version 22H2 for ARM64-based SystemsKB512287810.0.19045.7725
Windows 10 Version 22H2 for x64-based SystemsKB512287810.0.19045.7725
Windows 11 Version 23H2 for ARM64-based SystemsKB512288010.0.22631.7582
Windows 11 Version 23H2 for x64-based SystemsKB512288010.0.22631.7582
Windows 11 Version 24H2 for ARM64-based SystemsKB512400810.0.26100.9445
Windows 11 Version 24H2 for x64-based SystemsKB512400810.0.26100.9445
Windows 11 Version 25H2 for ARM64-based SystemsKB512400810.0.26200.9445
Windows 11 Version 25H2 for x64-based SystemsKB512400810.0.26200.9445
Windows 11 Version 26H1 for ARM64-based SystemsKB512401210.0.28000.2954
Windows 11 version 26H1 for x64-based SystemsKB512401210.0.28000.2954
Windows Server 2019 (Server Core installation) (x64)KB512287610.0.17763.9245
Windows Server 2019 (x64)KB512287610.0.17763.9245
Windows Server 2022 (Server Core installation) (x64)KB512288210.0.20348.5622
Windows Server 2022 (x64)KB512288210.0.20348.5622
Windows Server 2025 (Server Core installation) (x64)KB512287110.0.26100.33438
Windows Server 2025 (x64)KB512287110.0.26100.33438

Required remediation​

For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245. For Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.

For Windows 10 Version 21H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19044.7725. For Windows 10 Version 21H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725. For Windows 10 Version 21H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.

For Windows 10 Version 22H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19045.7725. For Windows 10 Version 22H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725. For Windows 10 Version 22H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.

For Windows 11 Version 23H2 for ARM64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582. For Windows 11 Version 23H2 for x64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.

For Windows 11 Version 24H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445. For Windows 11 Version 24H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.

For Windows 11 Version 25H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445. For Windows 11 Version 25H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.

For Windows 11 Version 26H1 for ARM64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954. For Windows 11 version 26H1 for x64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.

For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245. For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.

For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622. For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.

For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438. For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.

Administrator takeaway​

Deploy the applicable update through your normal Windows update-management process, restart devices where required, and validate the resulting OS build against the table above. For managed fleets, prioritize endpoints where standard users can run untrusted or attacker-supplied software, plus shared servers and jump hosts where a local foothold would be especially valuable.

 

References

  1. Official MSRC or vendor evidence api.msrc.microsoft.com
  2. Official MSRC or vendor evidence msrc.microsoft.com
  3. Official MSRC or vendor evidence api.msrc.microsoft.com