AI analysis
CVE-2026-69401 is a use-after-free (CWE-416) in the Audio Video Control Transport Protocol (AVCTP) component of Microsoft Windows, the protocol layer used to control Bluetooth audio and video devices. A local, authorized (low-privileged) attacker can trigger the flaw by interacting with the vulnerable protocol handling such that memory is freed while still in use, though the high attack-complexity score indicates reliable triggering is non-trivial. Successful exploitation lets the attacker elevate privileges locally on the affected machine, with high impact to confidentiality, integrity, and availability once elevated. Any Windows system that includes the AVCTP/Bluetooth component is affected, meaning a very broad portion of the Windows installed base. Exploitation status is currently calm: there is no known public proof-of-concept, the flaw is not in CISA KEV, EPSS is low at 0.2%, and the fix shipped as part of Microsoft's September 2026 Patch Tuesday (966 flaws fixed, including 2 zero-days).
What to do: Apply Microsoft's September 2026 Patch Tuesday security updates to all Windows endpoints as soon as patching windows allow, prioritizing shared, multi-user, or kiosk-style systems where untrusted local accounts exist. Since the bug requires an authorized local attacker, reduce exposure by limiting local sign-in rights and auditing which users hold accounts on sensitive machines. Consult Microsoft's advisory to identify the exact affected builds for your Windows versions, as the version ranges were not included in the data available here.
Affected
| Microsoft Windows (Audio Video Control Transport Protocol / Bluetooth AVCTP component) | — |
Estimated exposure
mass≈1 billion+ Windows installations (component ships with Windows) — Windows runs on more than a billion active devices worldwide and the AVCTP Bluetooth protocol component is included with the operating system, so the potentially affected population is the full Windows installed base, though exploitation…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.