ZeroHour

CVE-2026-69396

mass

Use-After-Free in Windows NDIS Enables Network-Based Privilege Escalation

CVSS 3.1
7.1 high
EPSS
<1%p43
Published
()
Modified
AI analysis

CVE-2026-69396 is a use-after-free vulnerability (CWE-416) in Windows NDIS, the Network Driver Interface Specification component that handles network communications in the Windows kernel. An authorized attacker who already holds low-privileged valid credentials could trigger the flaw remotely over the network; the CVSS vector indicates high attack complexity and some user interaction, making successful exploitation more difficult than a routine network attack. A successful exploit allows local privilege elevation to higher privileges on the target system, with high impact on confidentiality, integrity, and availability. Because NDIS is a core component of every Windows installation, all Windows deployments (client and server) are plausibly in scope, though Microsoft's advisory would define the specific affected builds. As of now there is no known public proof-of-concept, no CISA KEV listing, and a modest 0.5% EPSS probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69396 via Windows Update or WSUS as soon as it is released, and prioritize internet-reachable Windows hosts and multi-user environments where untrusted users hold low-privileged accounts. Until patching, restrict which accounts can authenticate to Windows hosts over the network and monitor for suspicious privilege-escalation activity. Check Microsoft's advisory to confirm which Windows client and server builds are affected and obtain the fixed builds, since the available data does not list specific version ranges.

Affected
Microsoft Windows NDIS (Windows operating systems)
Estimated exposure
mass≈1 billion+ Windows devices (NDIS is present by default in every Windows install) — Windows holds roughly 70% of desktop OS market share with over 1.4 billion active devices per public estimates, and NDIS is a default core networking component, so the potentially affected install base is on the order of a billion devices,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.