CVE-2026-69362
massLocal Privilege Elevation via Use-After-Free in Windows Error Reporting
CVE-2026-69362 is a use-after-free flaw (CWE-416) in the Windows Error Reporting (WER) component of Windows. An authorized attacker who already holds low-privileged access on a target machine can trigger the bug through WER's local processing; the high attack complexity (AC:H) suggests reliable exploitation depends on specific timing or memory-layout conditions. Successful exploitation elevates the attacker's privileges locally, with high impact on confidentiality, integrity, and availability on that host. Because WER is a built-in component present by default on essentially all Windows client and server installations, virtually any Windows system is potentially affected, pending Microsoft's version-specific advisory. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS is low (0.3% probability of exploitation within 30 days), indicating no observed exploitation yet.
What to do: Consult Microsoft's advisory for the affected Windows releases and apply the corresponding Patch Tuesday cumulative update via Windows Update; because this is a local, high-complexity bug with low EPSS, a normal patch cadence is acceptable, prioritizing shared or multi-user systems where untrusted users have local logon rights. Until patched, limit local sign-in on sensitive hosts to trusted accounts and monitor for any added public PoC, KEV listing, or observed exploitation.
| Microsoft Windows Error Reporting (Windows component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.