ZeroHour

CVE-2026-69341

mass

Use-After-Free Local Privilege Escalation in Windows Image Acquisition

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69341 is a use-after-free memory-corruption flaw (CWE-416) in the Windows Image Acquisition (WIA) component of Microsoft Windows. A local attacker who already holds valid low-privileged credentials can exercise WIA in a way that frees memory still in use and then reuses it, which — despite high exploitation complexity (AC:H) — can allow code execution in the elevated service context without any user interaction. Successful exploitation grants local privilege elevation, typically to SYSTEM/administrator level, letting the attacker fully compromise that host, persist, and pivot onward. Any Windows installation that ships the WIA component — effectively all supported Windows client and server systems — is affected, though the source data does not enumerate specific affected versions. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation within 30 days (17th percentile).

What to do: Apply Microsoft's current security (cumulative) update for affected Windows versions as soon as it is published, since the flaw requires only an authenticated local session and no user interaction. Until patching, prioritize hosts where untrusted users can log on locally — RDS/terminal servers, VDI, shared kiosks and workstations — and restrict local logon rights where practical. Note that the high attack complexity (AC:H) and low EPSS (0.3%) indicate near-term exploitation risk is low, but this LPE is a strong post-compromise escalation path, so patch as part of routine hygiene.

Affected
Microsoft Windows (Windows Image Acquisition / WIA component)
Estimated exposure
mass≈1 billion+ Windows installations (WIA ships as a standard Windows component) — Windows runs on roughly 1.4 billion devices worldwide and the Windows Image Acquisition component is included by default on supported Windows client and server releases, so essentially every Windows install carries the affected code.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.