ZeroHour

CVE-2026-69362

mass

Local Privilege Elevation via Use-After-Free in Windows Error Reporting

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69362 is a use-after-free flaw (CWE-416) in the Windows Error Reporting (WER) component of Windows. An authorized attacker who already holds low-privileged access on a target machine can trigger the bug through WER's local processing; the high attack complexity (AC:H) suggests reliable exploitation depends on specific timing or memory-layout conditions. Successful exploitation elevates the attacker's privileges locally, with high impact on confidentiality, integrity, and availability on that host. Because WER is a built-in component present by default on essentially all Windows client and server installations, virtually any Windows system is potentially affected, pending Microsoft's version-specific advisory. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS is low (0.3% probability of exploitation within 30 days), indicating no observed exploitation yet.

What to do: Consult Microsoft's advisory for the affected Windows releases and apply the corresponding Patch Tuesday cumulative update via Windows Update; because this is a local, high-complexity bug with low EPSS, a normal patch cadence is acceptable, prioritizing shared or multi-user systems where untrusted users have local logon rights. Until patched, limit local sign-in on sensitive hosts to trusted accounts and monitor for any added public PoC, KEV listing, or observed exploitation.

Affected
Microsoft Windows Error Reporting (Windows component)
Estimated exposure
mass≈1 billion+ Windows installations (WER ships with Windows by default) — WER is a default Windows component, so the exposed population broadly tracks the global Windows install base, which is well over 1 billion devices across desktops, laptops, and servers.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.