CVE-2026-69275
massUse-After-Free Local Privilege Escalation in Microsoft Windows Kernel Streaming WOW Thunk Driver
CVE-2026-69275 is a use-after-free (CWE-416) in the Kernel Streaming WOW Thunk Service Driver, a Windows kernel component used to support 32-bit (WOW) applications on 64-bit systems. An authorized local attacker who can already execute code on the machine with limited privileges can trigger the flaw by exploiting the freed-memory race condition in the driver, gaining elevation to higher privileges on the local system. Successful exploitation could allow an attacker to install programs, change or delete data, and create new accounts with full user rights. All systems running affected builds of Microsoft Windows are in scope, but the bug is not exploitable remotely and requires no user interaction. As of the data provided, there is no public proof-of-concept, it is not in the CISA KEV catalog, and EPSS assigns a low 0.2% probability of exploitation within 30 days, so no in-the-wild exploitation is known.
What to do: Apply Microsoft's security update for CVE-2026-69275 as soon as it is available, prioritizing shared workstations, developer machines, and servers that let standard users run 32-bit (WOW) applications locally. Since this is a local privilege escalation with a high attack-complexity rating, treat it as a hardening patch rather than an urgent fire drill, but verify that no in-the-wild exploit has emerged before deferring it in your patch cycle. Check your patch management reports for machines still missing the applicable Windows update.
| Microsoft Windows (Kernel Streaming WOW Thunk Service Driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.