CVE-2026-69335
massUse-After-Free in Microsoft Windows Win32K Allows Local Privilege Escalation
CVE-2026-69335 is a use-after-free memory corruption flaw (CWE-416) in the Windows Win32K kernel component, assigned by Microsoft. It is triggered locally by an authorized attacker who already holds low privileges on the system; the high attack complexity indicates the trigger conditions are timing- or state-dependent, and no user interaction is required. A successful exploit lets the attacker elevate privileges locally, with high impact on confidentiality, integrity, and availability on the compromised host. All Windows editions that ship the Win32K driver are plausibly in scope, though the affected build list is not included in the available data. Exploitation status is quiet: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69335 as soon as your patch cycle allows, checking Microsoft's advisory for the exact affected builds and KB packages since they are not enumerated in this data. Because this is a local privilege escalation requiring an authorized low-privileged user, limit local logon rights on sensitive hosts and review which users hold interactive access. Monitor for emergence of a public PoC or KEV listing, as the low EPSS (0.3%) suggests exploitation risk is currently modest.
| Microsoft Windows (Win32K component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.