ZeroHour

CVE-2026-69281

mass

Use-After-Free Local Privilege Elevation in Microsoft Windows License Manager

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69281 is a use-after-free (CWE-416) memory-safety flaw in the Windows License Manager, a component of Microsoft Windows. A local attacker who is already authorized on the machine (low privileges required) can trigger the flaw by causing the License Manager service to use memory that has been freed; the high attack-complexity score suggests timing or state conditions must line up for the bug to be triggered reliably. Successful exploitation lets the attacker elevate privileges on the local system, with high impact on confidentiality, integrity, and availability at the elevated level. Any Windows installation containing the affected License Manager component is in scope, per Microsoft's advisory (specific version ranges were not provided in the source data). There is currently no known exploitation in the wild, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69281 as part of your regular monthly patch cycle, prioritizing shared workstations, terminal servers, and other systems where untrusted or low-privilege users can log on locally. Because exploitation requires local access and there is no public PoC, broad emergency mitigation is not required; in the interim, limit interactive logon rights on sensitive hosts and watch EDR telemetry for unusual local privilege-elevation activity involving the License Manager service.

Affected
Microsoft Windows (License Manager component)
Estimated exposure
masshundreds of millions to over a billion Windows endpoints (License Manager is a built-in Windows component) — The License Manager ships as part of Windows, so exposure scales with the roughly billion-plus active Windows devices worldwide, though only versions confirmed in Microsoft's advisory are actually vulnerable.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows License Manager allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.