ZeroHour

CVE-2026-69357

mass

Use-After-Free in Windows NDIS Enables Network-Based Privilege Escalation

CVSS 3.1
7.1 high
EPSS
<1%p34
Published
()
Modified
AI analysis

CVE-2026-69357 is a use-after-free (CWE-416) memory-safety flaw in Windows NDIS, the component that sits between the Windows networking stack and network adapter drivers. Per the CVSS vector, exploitation requires an attacker who already holds valid low-privileged network access (AV:N, PR:L) and involves user interaction and favorable timing conditions (UI:R, AC:H), making successful remote triggering harder than in a typical network attack. An attacker who successfully triggers the flaw gains elevated privileges on the target host with full confidentiality, integrity, and availability impact (C:H/I:H/A:H). Affected parties are organizations running the affected Windows builds (exact version ranges are not included in the source data and must be taken from Microsoft's bulletin), which effectively means nearly any Windows deployment, given that NDIS is present on essentially all Windows systems. Exploitation is not currently observed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns it just a 0.4% probability of exploitation within 30 days (34th percentile), though the high impact warrants routine patching.

What to do: Apply Microsoft's security update for CVE-2026-69357 on the normal patch cycle and check Microsoft's advisory for the specific affected Windows builds, since the source data does not list version ranges. Because exploitation requires valid low-privileged credentials plus user interaction, prioritize patching internet-exposed or multi-user hosts such as RDS/VPN servers, and in the interim limit low-privileged network access to sensitive systems. No known PoC or in-the-wild exploitation exists, so standard patching discipline is sufficient at this time.

Affected
Microsoft Windows (NDIS networking component)
Estimated exposure
mass≈1 billion+ Windows installations (Microsoft has reported over 1 billion active Windows devices, nearly all of which include the NDIS stack) — The NDIS component ships with effectively every Windows installation, and Microsoft's publicly reported device base exceeds one billion, making the plausible exposure the entire installed Windows base across consumer, enterprise, and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.