CVE-2026-69299
massLocal Privilege Escalation via Use-After-Free in Microsoft COM for Windows
CVE-2026-69299 is a use-after-free memory corruption flaw in Microsoft's Component Object Model (COM) runtime for Windows. An attacker who already has authorized local access with low privileges can trigger the flaw, in which COM frees a memory object that is subsequently reused, without requiring user interaction. Successful exploitation allows the attacker to elevate privileges locally on the affected machine, with high impact on confidentiality, integrity, and availability, though the high attack-complexity rating suggests reliable exploitation is not trivial. Any Windows system that includes the COM runtime is affected; the available data does not enumerate specific Windows versions. There is currently no known exploitation in the wild, no public proof-of-concept, and the flaw is not in CISA's KEV catalog, with EPSS estimating only a 0.2% chance of exploitation within 30 days.
What to do: Apply the Microsoft Windows security update that addresses CVE-2026-69299 via Windows Update as soon as it is released, and verify patch status on servers and workstations. Until patched, restrict local logon and low-privilege code execution on sensitive Windows hosts to trusted accounts, since exploitation requires an authorized local user. Monitor Microsoft's advisory for the definitive list of affected versions and any change in exploitation status.
| Microsoft COM for Windows (Component Object Model runtime shipped with Microsoft Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Microsoft COM for Windows allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.