Microsoft assigns the issue a CVSS base score of 7.1 and a CVSS temporal score of 6.2. Its full CVSS vector is:
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Publicly disclosed: No
Exploited: No
Customer action required: Yes
Microsoft’s exploitation assessment is Exploitation Unlikely. That assessment should not be mistaken for a reason to postpone patching: successful exploitation could give an attacker SYSTEM privileges, the highest local privilege level on a Windows machine.
What CVE-2026-69688 means
The affected Windows component is Encrypting File System, or EFS, a Windows feature that supports file-level encryption. According to Microsoft’s advisory, the vulnerability is specifically a heap-based buffer overflow that permits an authorized attacker to elevate privileges over a network.
The network attack vector is important, but so are the conditions embedded in the CVSS score. An attacker needs low privileges and user interaction, while the attack complexity is rated high. Microsoft explains that successful exploitation requires “a deep understanding of the system” and is not guaranteed; its success can depend on environmental factors, system configuration, and additional security measures.
In practical terms, this is not the sort of flaw that turns every unpatched PC into instant internet roadkill. It is nevertheless a serious post-access risk. An attacker who already has some level of authorized access could potentially use the flaw to move from limited permissions to SYSTEM. For administrators, that makes patching part of the normal defense-in-depth routine: reducing opportunities for an attacker to turn an initial foothold into control of a workstation or server.
Patch priority and deployment guidance
CVE-2026-69688 spans Windows 10, Windows 11, and Windows Server releases, including Server Core installations. Organizations should identify systems by their Windows release and architecture, deploy the listed cumulative update, restart if required by their servicing process, and verify that the machine has reached the stated fixed build.
The practical verification point is the OS build number, not merely whether a KB is listed in an update history. Shared KB packages can correspond to different target builds across Windows versions.
Windows 10 remediation
| Affected product | Required update | Fixed build |
|---|---|---|
| Windows 10 Version 1607 for 32-bit Systems (x86) | KB5123099 | 10.0.14393.9512 |
| Windows 10 Version 1607 for x64-based Systems | KB5123099 | 10.0.14393.9512 |
| Windows 10 Version 1809 for 32-bit Systems (x86) | KB5122876 | 10.0.17763.9245 |
| Windows 10 Version 1809 for x64-based Systems | KB5122876 | 10.0.17763.9245 |
| Windows 10 Version 21H2 for 32-bit Systems (x86) | KB5122878 | 10.0.19044.7725 |
| Windows 10 Version 21H2 for ARM64-based Systems | KB5122878 | 10.0.19044.7725 |
| Windows 10 Version 21H2 for x64-based Systems | KB5122878 | 10.0.19044.7725 |
| Windows 10 Version 22H2 for 32-bit Systems (x86) | KB5122878 | 10.0.19045.7725 |
| Windows 10 Version 22H2 for ARM64-based Systems | KB5122878 | 10.0.19045.7725 |
| Windows 10 Version 22H2 for x64-based Systems | KB5122878 | 10.0.19045.7725 |
For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512. For Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512. For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245. For Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245. For Windows 10 Version 21H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19044.7725. For Windows 10 Version 21H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725. For Windows 10 Version 21H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725. For Windows 10 Version 22H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19045.7725. For Windows 10 Version 22H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725. For Windows 10 Version 22H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
Windows 11 remediation
| Affected product | Required update | Fixed build |
|---|---|---|
| Windows 11 Version 23H2 for ARM64-based Systems | KB5122880 | 10.0.22631.7582 |
| Windows 11 Version 23H2 for x64-based Systems | KB5122880 | 10.0.22631.7582 |
| Windows 11 Version 24H2 for ARM64-based Systems | KB5124008 | 10.0.26100.9445 |
| Windows 11 Version 24H2 for x64-based Systems | KB5124008 | 10.0.26100.9445 |
| Windows 11 Version 25H2 for ARM64-based Systems | KB5124008 | 10.0.26200.9445 |
| Windows 11 Version 25H2 for x64-based Systems | KB5124008 | 10.0.26200.9445 |
| Windows 11 Version 26H1 for ARM64-based Systems | KB5124012 | 10.0.28000.2954 |
| Windows 11 version 26H1 for x64-based Systems | KB5124012 | 10.0.28000.2954 |
For Windows 11 Version 23H2 for ARM64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582. For Windows 11 Version 23H2 for x64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582. For Windows 11 Version 24H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445. For Windows 11 Version 24H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445. For Windows 11 Version 25H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445. For Windows 11 Version 25H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445. For Windows 11 Version 26H1 for ARM64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954. For Windows 11 version 26H1 for x64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
Windows Server remediation
| Affected product | Required update | Fixed build |
|---|---|---|
| Windows Server 2012 (Server Core installation) (x64) | KB5123065 | 6.2.9200.26349 |
| Windows Server 2012 (x64) | KB5123065 | 6.2.9200.26349 |
| Windows Server 2012 R2 (Server Core installation) (x64) | KB5123066 | 6.3.9600.23398 |
| Windows Server 2012 R2 (x64) | KB5123066 | 6.3.9600.23398 |
| Windows Server 2016 (Server Core installation) (x64) | KB5123099 | 10.0.14393.9512 |
| Windows Server 2016 (x64) | KB5123099 | 10.0.14393.9512 |
| Windows Server 2019 (Server Core installation) (x64) | KB5122876 | 10.0.17763.9245 |
| Windows Server 2019 (x64) | KB5122876 | 10.0.17763.9245 |
| Windows Server 2022 (Server Core installation) (x64) | KB5122882 | 10.0.20348.5622 |
| Windows Server 2022 (x64) | KB5122882 | 10.0.20348.5622 |
| Windows Server 2025 (Server Core installation) (x64) | KB5122871 | 10.0.26100.33438 |
| Windows Server 2025 (x64) | KB5122871 | 10.0.26100.33438 |
For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349. For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349. For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23398. For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23398. For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512. For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512. For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245. For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245. For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622. For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622. For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438. For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
What administrators should do now
- Inventory Windows endpoints and servers against the affected product list, including Server Core deployments.
- Deploy the appropriate cumulative update through the organization’s normal Windows update-management process.
- Restart systems where required so the updated EFS components are loaded.
- Confirm the resulting OS build matches the fixed build for the specific Windows release and architecture.
- Prioritize systems where authorized users have network access to EFS-capable Windows hosts, especially shared infrastructure and servers with a large administrative blast radius.
The headline risk is privilege escalation to SYSTEM after an attacker has already met the vulnerability’s preconditions. Microsoft rates exploitation as unlikely and notes the high complexity involved, but successful escalation is exactly the kind of step attackers prize when trying to turn restricted access into full machine control. Apply the relevant KB and verify the build; it is a comparatively straightforward piece of security hygiene, even if the underlying bug is anything but.
References
- Official MSRC or vendor evidence api.msrc.microsoft.com
- Official MSRC or vendor evidence msrc.microsoft.com
- Official MSRC or vendor evidence api.msrc.microsoft.com