CVE-2026-69396
massUse-After-Free in Windows NDIS Enables Network-Based Privilege Escalation
CVE-2026-69396 is a use-after-free vulnerability (CWE-416) in Windows NDIS, the Network Driver Interface Specification component that handles network communications in the Windows kernel. An authorized attacker who already holds low-privileged valid credentials could trigger the flaw remotely over the network; the CVSS vector indicates high attack complexity and some user interaction, making successful exploitation more difficult than a routine network attack. A successful exploit allows local privilege elevation to higher privileges on the target system, with high impact on confidentiality, integrity, and availability. Because NDIS is a core component of every Windows installation, all Windows deployments (client and server) are plausibly in scope, though Microsoft's advisory would define the specific affected builds. As of now there is no known public proof-of-concept, no CISA KEV listing, and a modest 0.5% EPSS probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69396 via Windows Update or WSUS as soon as it is released, and prioritize internet-reachable Windows hosts and multi-user environments where untrusted users hold low-privileged accounts. Until patching, restrict which accounts can authenticate to Windows hosts over the network and monitor for suspicious privilege-escalation activity. Check Microsoft's advisory to confirm which Windows client and server builds are affected and obtain the fixed builds, since the available data does not list specific version ranges.
| Microsoft Windows NDIS (Windows operating systems) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.