• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-69328: local privilege escalation in Microsoft Windows 10 Version 1607

A local, authorized attacker can elevate privileges on Windows 10 Version 1607 and related Windows releases by exploiting an untrusted search path in Windows storage components (CVE-2026-69328). Affected builds span multiple Windows 10, Windows 11, and Windows Server branches (for example 10.0.14393.0 through before 10.0.14393.9512 for Version 1607); an attacker requires local access and an authorized account to trigger the issue.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
7.8HIGH
EPSS
0.00457
CWE
CWE-426
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: apply the vendor fixes immediately because public exploit code exists for this untrusted-search-path privilege escalation. Patch exposed and reachable systems without delay.

What is CVE-2026-69328?

A local, authorized attacker can elevate privileges on Windows 10 Version 1607 and related Windows releases by exploiting an untrusted search path in Windows storage components (CVE-2026-69328). Affected builds span multiple Windows 10, Windows 11, and Windows Server branches (for example 10.0.14393.0 through before 10.0.14393.9512 for Version 1607); an attacker requires local access and an authorized account to trigger the issue.

Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2016 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512

Is CVE-2026-69328 being exploited?

Public exploit code is available.

How to fix CVE-2026-69328

  1. Install the provided security updates that include the fixes (for example update Version 1607 to 10.0.14393.9512).
  2. Update other affected branches to their fixed builds (examples: 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954).
  3. If you cannot patch immediately, restrict local access to affected systems and monitor for suspicious local privilege escalation activity.
  4. Follow Microsoft guidance and verify installations by checking build numbers after updates are applied.

Frequently asked questions

Is CVE-2026-69328 being actively exploited?

Public exploit code is available for CVE-2026-69328.

Which Windows 10 Version 1607 versions are affected by CVE-2026-69328?

Windows 10 Version 1607 builds from 10.0.14393.0 up to but not including 10.0.14393.9512 are affected.

Is there a patch for CVE-2026-69328?

Yes. Microsoft released fixed builds such as 10.0.14393.9512 for Version 1607 and corresponding fixed builds for other affected branches.

Does CVE-2026-69328 require authentication?

Yes. The issue requires a local, authorized user account to exploit the untrusted search path vulnerability.

References