CVE-2026-69333
massUse-After-Free Local Privilege Escalation in Microsoft Windows Win32K
CVE-2026-69333 is a use-after-free memory-corruption flaw (CWE-416) in the Windows Win32K kernel component that allows an authorized local user to elevate privileges. To trigger it, an attacker who already holds valid low-privileged credentials must drive the kernel into a code path where freed memory is still referenced, which CVSS rates as high attack complexity with no user interaction required. Successful exploitation yields code execution in kernel context, giving the attacker high-privilege (SYSTEM-level) control over confidentiality, integrity, and availability on the host. Any Windows system shipping the Win32K component is potentially affected, though the available data does not specify which Windows versions or branches are impacted. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days, indicating no known in-the-wild exploitation.
What to do: Monitor Microsoft's security advisory for CVE-2026-69333 and apply the corresponding Windows security update via Windows Update or WSUS as soon as it is released, prioritizing endpoints where untrusted or low-privileged users log on interactively. In the meantime, limit interactive logon rights on servers to trusted administrators, and check vendor channels for confirmation of which Windows versions are in scope since the affected ranges are not yet detailed in the available data.
| Microsoft Windows (Win32K kernel component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.