CVE-2026-68847
massUse-After-Free Local Privilege Escalation in Windows Connected User Experiences and Telemetry
CVE-2026-68847 is a use-after-free vulnerability (CWE-416) in the Windows Connected User Experiences and Telemetry component. It is triggered by an attacker who already has low-privileged access on the local machine and can get the component into a state where freed memory is reused, a condition rated as high attack complexity and requiring no user interaction. Successful exploitation allows elevation of privileges on the local system, with high impact on confidentiality, integrity, and availability of the host. Any Windows installation carrying this component is affected; the vendor has not published specific affected version ranges in the available data. No public proof-of-concept, KEV listing, or in-the-wild exploitation is known, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.
What to do: Check Microsoft's security advisory for CVE-2026-68847 and apply the associated Windows update through your normal patch cycle, prioritizing hosts where multiple unprivileged users can run code. As an interim measure, limit local code execution by untrusted or low-privileged users on sensitive systems and verify whether the Connected User Experiences and Telemetry service is running as expected. Because no public exploit or in-the-wild exploitation is known and EPSS is low, treat this as routine patching rather than emergency response.
| Microsoft Windows (Connected User Experiences and Telemetry component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.