CVE-2026-69451
PoC massUse-After-Free Elevation of Privilege in Microsoft Windows Management Instrumentation
CVE-2026-69451 is a use-after-free (CWE-416) in Windows Management Instrumentation (WMI), the core management infrastructure component of Microsoft Windows. An authorized attacker holding only a low-privileged account can reach the flaw over a network and trigger it with user interaction and under high attack complexity, likely by racing WMI operations to free and reuse an object. Successful exploitation grants the attacker elevated privileges on the target system, with high confidentiality, integrity, and availability impact per the CVSS 7.1 score. All Windows systems carrying the affected WMI component are potentially affected; the available data does not specify exact affected version ranges or builds, so defenders should consult Microsoft's advisory. Exploitation has not yet been added to CISA KEV and EPSS is only ~0.7% (50th percentile), but one public proof-of-concept is available, and no confirmed in-the-wild exploitation is documented.
What to do: Install the Microsoft security update for CVE-2026-69451 as soon as it is available through Windows Update/WSUS, checking Microsoft's advisory for the exact affected builds since version ranges are not listed in the source data. Prioritize patching multi-user hosts such as RDS/VDI servers where low-privileged remote users log in, since exploitation requires an authorized account plus user interaction. Note that a public PoC exists, so monitor WMI-related process and event logs for anomalous activity until systems are patched.
| Microsoft Windows (Windows Management Instrumentation / WMI component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.