CVE-2026-69324
massLocal privilege elevation via type confusion in Windows Performance Monitor
CVE-2026-69324 is a type confusion flaw (also mapped to out-of-bounds read, CWE-125) in the Windows Performance Monitor component. An authorized attacker, meaning a user with an existing low-privileged local account, can trigger the flaw without needing any user interaction. Successful exploitation allows the attacker to elevate privileges locally, with high impact on confidentiality, integrity, and availability on the compromised machine. Any Windows system that includes the Performance Monitor component is potentially affected; the available data does not specify the affected Windows version ranges. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 0.3% probability of exploitation within 30 days (25th percentile).
What to do: Apply Microsoft's security update for CVE-2026-69324 through Windows Update as soon as it is available, prioritizing systems where multiple interactive users log on locally, such as terminal/RDS servers and shared workstations. In the interim, restrict local logon rights to trusted accounts and review which users hold local access on sensitive hosts. Monitor for a public PoC or CISA KEV listing, since current indicators (EPSS 0.3%, no KEV entry, no known PoC) suggest low near-term exploitation risk.
| Microsoft Windows (Performance Monitor component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Access of resource using incompatible type ('type confusion') in Windows Performance Monitor allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-125, CWE-843
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.