ZeroHour

CVE-2026-69410

mass

Use-After-Free Local Privilege Escalation in Windows Win32K

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69410 is a use-after-free (CWE-416) in Windows Win32K, the kernel-mode component that handles graphics and windowing (GUI) system calls. A low-privileged but authorized local attacker (e.g., a user or malware already running on the machine) can trigger the memory-reuse flaw to corrupt kernel memory and execute code with elevated privileges; the attack requires no user interaction but is rated high attack complexity. Successful exploitation yields local privilege escalation, typically to SYSTEM/kernel-level control of the host, with high impact on confidentiality, integrity, and availability. Because Win32K is a core component of Windows, essentially all Windows client and server-with-desktop systems are in scope, though only systems where an attacker can already run code locally are practically exposed. As of this analysis there is no known in-the-wild exploitation, no public proof-of-concept, and EPSS puts 30-day exploitation probability at just 0.3% (17th percentile); the issue is not in CISA KEV.

What to do: Patch via the Microsoft monthly security/cumulative update addressing CVE-2026-69410 once released; do not invent a KB or build number—check Microsoft's advisory for the exact affected versions and fixed builds. Because exploitation requires an attacker to already run low-privileged code locally, prioritize endpoints exposed to untrusted users, and enforce least-privilege local access. No workaround or public PoC is known; monitor the dashboard for changes in KEV listing or EPSS.

Affected
Microsoft Windows (Win32K kernel component)
Estimated exposure
mass≈1 billion+ Windows installations (Win32K ships in every Windows client OS and server-with-Desktop-Experience) — Win32K is a core kernel component present on effectively all Windows client and desktop-server installations, and Microsoft has publicly reported over a billion active Windows devices, though practical exploitability requires local code…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.