ZeroHour

CVE-2026-69275

mass

Use-After-Free Local Privilege Escalation in Microsoft Windows Kernel Streaming WOW Thunk Driver

CVSS 3.1
7.0 high
EPSS
<1%p9
Published
()
Modified
AI analysis

CVE-2026-69275 is a use-after-free (CWE-416) in the Kernel Streaming WOW Thunk Service Driver, a Windows kernel component used to support 32-bit (WOW) applications on 64-bit systems. An authorized local attacker who can already execute code on the machine with limited privileges can trigger the flaw by exploiting the freed-memory race condition in the driver, gaining elevation to higher privileges on the local system. Successful exploitation could allow an attacker to install programs, change or delete data, and create new accounts with full user rights. All systems running affected builds of Microsoft Windows are in scope, but the bug is not exploitable remotely and requires no user interaction. As of the data provided, there is no public proof-of-concept, it is not in the CISA KEV catalog, and EPSS assigns a low 0.2% probability of exploitation within 30 days, so no in-the-wild exploitation is known.

What to do: Apply Microsoft's security update for CVE-2026-69275 as soon as it is available, prioritizing shared workstations, developer machines, and servers that let standard users run 32-bit (WOW) applications locally. Since this is a local privilege escalation with a high attack-complexity rating, treat it as a hardening patch rather than an urgent fire drill, but verify that no in-the-wild exploit has emerged before deferring it in your patch cycle. Check your patch management reports for machines still missing the applicable Windows update.

Affected
Microsoft Windows (Kernel Streaming WOW Thunk Service Driver)
Estimated exposure
masshundreds of millions to billions of Windows installations (Windows runs on roughly 70%+ of the desktop OS market; all affected Windows editions include the… — The driver is a standard component of 64-bit Windows shipping on essentially all affected Windows desktops and servers, so exposure is scaled from public Windows market-share and installed-base estimates rather than a per-asset count.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.