CVE-2026-69672
Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally.
CVSS
5.5
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-908
Not enough EPSS history yet.
Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-858807.8 HIG—
———Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.5hCVE-2026-819585.5 MED—
———Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.5hCVE-2026-813915.5 MED—
———Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.5hCVE-2026-800916.5 MED—
———Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network.5hCVE-2026-785198.8 HIG—
———Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.5hCVE-2026-729897.5 HIG—
———Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.5h