Program Compatibility Assistant Service
by Microsoft
CVEs (8)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-68876 | Hig | 0.52 | 8.0 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-69534 | Hig | 0.51 | 7.8 | 0.01 | Sep 8, 2026 | Improper neutralization of special elements used in a command ('command injection') in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-68845 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62696 | Hig | 0.51 | 7.8 | 0.03 | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-45487 | Hig | 0.51 | 7.8 | 0.00 | Jun 9, 2026 | Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-69563 | Hig | 0.45 | 7.0 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-68874 | Med | 0.37 | 5.7 | 0.01 | Sep 8, 2026 | Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-68873 | Med | 0.36 | 5.5 | 0.00 | Sep 8, 2026 | Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally. |
- risk 0.52cvss 8.0epss 0.01
Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges over a network.
- risk 0.51cvss 7.8epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.03
Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
- risk 0.45cvss 7.0epss 0.00
Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
- risk 0.37cvss 5.7epss 0.01
Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information over a network.
- risk 0.36cvss 5.5epss 0.00
Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally.