CVE-2026-69410
massUse-After-Free Local Privilege Escalation in Windows Win32K
CVE-2026-69410 is a use-after-free (CWE-416) in Windows Win32K, the kernel-mode component that handles graphics and windowing (GUI) system calls. A low-privileged but authorized local attacker (e.g., a user or malware already running on the machine) can trigger the memory-reuse flaw to corrupt kernel memory and execute code with elevated privileges; the attack requires no user interaction but is rated high attack complexity. Successful exploitation yields local privilege escalation, typically to SYSTEM/kernel-level control of the host, with high impact on confidentiality, integrity, and availability. Because Win32K is a core component of Windows, essentially all Windows client and server-with-desktop systems are in scope, though only systems where an attacker can already run code locally are practically exposed. As of this analysis there is no known in-the-wild exploitation, no public proof-of-concept, and EPSS puts 30-day exploitation probability at just 0.3% (17th percentile); the issue is not in CISA KEV.
What to do: Patch via the Microsoft monthly security/cumulative update addressing CVE-2026-69410 once released; do not invent a KB or build number—check Microsoft's advisory for the exact affected versions and fixed builds. Because exploitation requires an attacker to already run low-privileged code locally, prioritize endpoints exposed to untrusted users, and enforce least-privilege local access. No workaround or public PoC is known; monitor the dashboard for changes in KEV listing or EPSS.
| Microsoft Windows (Win32K kernel component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.