AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-70347

HIGH · CVSS 7.8 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A heap-based buffer overflow vulnerability in Windows Installer allows authorized attackers to elevate their privileges locally, potentially granting them unauthorized access to sensitive system resources. Organizations using affected Windows versions should prioritize patching this vulnerability to mitigate the risk of exploitation. This is particularly critical for environments where users have administrative privileges or where sensitive data is handled.

CVE
CVE-2026-70347
Severity
HIGH
CVSS
7.8
EPSS
0.31%
Windows

Original NVD Description

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

Related CVEs

Other vulnerabilities affecting the same vendor(s)