ZeroHour

CVE-2026-69324

mass

Local privilege elevation via type confusion in Windows Performance Monitor

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69324 is a type confusion flaw (also mapped to out-of-bounds read, CWE-125) in the Windows Performance Monitor component. An authorized attacker, meaning a user with an existing low-privileged local account, can trigger the flaw without needing any user interaction. Successful exploitation allows the attacker to elevate privileges locally, with high impact on confidentiality, integrity, and availability on the compromised machine. Any Windows system that includes the Performance Monitor component is potentially affected; the available data does not specify the affected Windows version ranges. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 0.3% probability of exploitation within 30 days (25th percentile).

What to do: Apply Microsoft's security update for CVE-2026-69324 through Windows Update as soon as it is available, prioritizing systems where multiple interactive users log on locally, such as terminal/RDS servers and shared workstations. In the interim, restrict local logon rights to trusted accounts and review which users hold local access on sensitive hosts. Monitor for a public PoC or CISA KEV listing, since current indicators (EPSS 0.3%, no KEV entry, no known PoC) suggest low near-term exploitation risk.

Affected
Microsoft Windows (Performance Monitor component)
Estimated exposure
mass≈1 billion+ Windows installations (component is built into Windows) — Performance Monitor is a default component of Windows client and server editions, and Windows is deployed on well over a billion devices worldwide, so every unpatched Windows installation carries the vulnerable code even though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Access of resource using incompatible type ('type confusion') in Windows Performance Monitor allows an authorized attacker to elevate privileges locally.

Weakness
CWE-125, CWE-843
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.