ZeroHour

CVE-2026-69337

mass

Double-Free Privilege Escalation in Microsoft Windows Registry

CVSS 3.1
7.1 high
EPSS
<1%p49
Published
()
Modified
AI analysis

CVE-2026-69337 is a double-free memory-corruption flaw (CWE-415) in the Windows Registry component of Microsoft Windows, rated 7.1 (High) on the CVSS 3.1 scale. To trigger it, an attacker must already hold valid low-privileged credentials and reach the vulnerable code path over the network; the attack carries high complexity and requires user interaction, making reliable exploitation more difficult. On success, the attacker elevates privileges, with high impact to confidentiality, integrity, and availability beyond the compromised account's original rights. Any Windows installation with the affected Registry component is potentially exposed, although the affected version ranges are not specified in the available data. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at roughly 0.7% (median range), indicating no known exploitation.

What to do: Watch Microsoft's security advisory for this CVE to confirm which Windows versions are affected, and apply the corresponding security update as soon as it is released. Because exploitation requires valid low-privileged credentials plus user interaction, reduce exposure by reviewing which accounts can reach the host over the network and disabling or restricting services such as Remote Registry where they are not needed. Until patching is complete, prioritize hosts where untrusted or low-privilege users can execute code.

Affected
Microsoft Windows (Registry component)
Estimated exposure
mass≈1 billion+ Windows devices (global Windows install base), limited to those running affected versions once confirmed — The Windows Registry is present in every Windows installation and Windows is publicly estimated to run on more than a billion active devices, so the theoretical exposure base is the entire Windows fleet, narrowed once Microsoft specifies…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Double free in Windows Registry allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-415
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.