ZeroHour

CVE-2026-69401

mass

Use-After-Free Local Privilege Escalation in Microsoft Windows AVCTP Component

CVSS 3.1
7.0 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-69401 is a use-after-free (CWE-416) in the Audio Video Control Transport Protocol (AVCTP) component of Microsoft Windows, the protocol layer used to control Bluetooth audio and video devices. A local, authorized (low-privileged) attacker can trigger the flaw by interacting with the vulnerable protocol handling such that memory is freed while still in use, though the high attack-complexity score indicates reliable triggering is non-trivial. Successful exploitation lets the attacker elevate privileges locally on the affected machine, with high impact to confidentiality, integrity, and availability once elevated. Any Windows system that includes the AVCTP/Bluetooth component is affected, meaning a very broad portion of the Windows installed base. Exploitation status is currently calm: there is no known public proof-of-concept, the flaw is not in CISA KEV, EPSS is low at 0.2%, and the fix shipped as part of Microsoft's September 2026 Patch Tuesday (966 flaws fixed, including 2 zero-days).

What to do: Apply Microsoft's September 2026 Patch Tuesday security updates to all Windows endpoints as soon as patching windows allow, prioritizing shared, multi-user, or kiosk-style systems where untrusted local accounts exist. Since the bug requires an authorized local attacker, reduce exposure by limiting local sign-in rights and auditing which users hold accounts on sensitive machines. Consult Microsoft's advisory to identify the exact affected builds for your Windows versions, as the version ranges were not included in the data available here.

Affected
Microsoft Windows (Audio Video Control Transport Protocol / Bluetooth AVCTP component)
Estimated exposure
mass≈1 billion+ Windows installations (component ships with Windows) — Windows runs on more than a billion active devices worldwide and the AVCTP Bluetooth protocol component is included with the operating system, so the potentially affected population is the full Windows installed base, though exploitation…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Audio Video Control Transport Protocol allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1