ZeroHour

CVE-2026-69335

mass

Use-After-Free in Microsoft Windows Win32K Allows Local Privilege Escalation

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69335 is a use-after-free memory corruption flaw (CWE-416) in the Windows Win32K kernel component, assigned by Microsoft. It is triggered locally by an authorized attacker who already holds low privileges on the system; the high attack complexity indicates the trigger conditions are timing- or state-dependent, and no user interaction is required. A successful exploit lets the attacker elevate privileges locally, with high impact on confidentiality, integrity, and availability on the compromised host. All Windows editions that ship the Win32K driver are plausibly in scope, though the affected build list is not included in the available data. Exploitation status is quiet: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69335 as soon as your patch cycle allows, checking Microsoft's advisory for the exact affected builds and KB packages since they are not enumerated in this data. Because this is a local privilege escalation requiring an authorized low-privileged user, limit local logon rights on sensitive hosts and review which users hold interactive access. Monitor for emergence of a public PoC or KEV listing, as the low EPSS (0.3%) suggests exploitation risk is currently modest.

Affected
Microsoft Windows (Win32K component)
Estimated exposure
masshundreds of millions to >1 billion Windows devices (Win32K ships in all modern Windows client and server editions) — Windows runs on over a billion active devices worldwide and the Win32K driver is present across client and server editions, so the potential installed base is at the mass scale even though exploitation requires local access and the exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.