ZeroHour

CVE-2026-68847

mass

Use-After-Free Local Privilege Escalation in Windows Connected User Experiences and Telemetry

CVSS 3.1
7.0 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-68847 is a use-after-free vulnerability (CWE-416) in the Windows Connected User Experiences and Telemetry component. It is triggered by an attacker who already has low-privileged access on the local machine and can get the component into a state where freed memory is reused, a condition rated as high attack complexity and requiring no user interaction. Successful exploitation allows elevation of privileges on the local system, with high impact on confidentiality, integrity, and availability of the host. Any Windows installation carrying this component is affected; the vendor has not published specific affected version ranges in the available data. No public proof-of-concept, KEV listing, or in-the-wild exploitation is known, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.

What to do: Check Microsoft's security advisory for CVE-2026-68847 and apply the associated Windows update through your normal patch cycle, prioritizing hosts where multiple unprivileged users can run code. As an interim measure, limit local code execution by untrusted or low-privileged users on sensitive systems and verify whether the Connected User Experiences and Telemetry service is running as expected. Because no public exploit or in-the-wild exploitation is known and EPSS is low, treat this as routine patching rather than emergency response.

Affected
Microsoft Windows (Connected User Experiences and Telemetry component)
Estimated exposure
mass≈1 billion+ Windows installations (component ships with Windows by default) — The Connected User Experiences and Telemetry component is present by default on supported Windows installations, and the Windows installed base is publicly estimated at over a billion devices, so affected systems are plausibly in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.