ZeroHour

CVE-2026-69451

PoC mass

Use-After-Free Elevation of Privilege in Microsoft Windows Management Instrumentation

CVSS 3.1
7.1 high
EPSS
<1%p50
Published
()
Modified
AI analysis

CVE-2026-69451 is a use-after-free (CWE-416) in Windows Management Instrumentation (WMI), the core management infrastructure component of Microsoft Windows. An authorized attacker holding only a low-privileged account can reach the flaw over a network and trigger it with user interaction and under high attack complexity, likely by racing WMI operations to free and reuse an object. Successful exploitation grants the attacker elevated privileges on the target system, with high confidentiality, integrity, and availability impact per the CVSS 7.1 score. All Windows systems carrying the affected WMI component are potentially affected; the available data does not specify exact affected version ranges or builds, so defenders should consult Microsoft's advisory. Exploitation has not yet been added to CISA KEV and EPSS is only ~0.7% (50th percentile), but one public proof-of-concept is available, and no confirmed in-the-wild exploitation is documented.

What to do: Install the Microsoft security update for CVE-2026-69451 as soon as it is available through Windows Update/WSUS, checking Microsoft's advisory for the exact affected builds since version ranges are not listed in the source data. Prioritize patching multi-user hosts such as RDS/VDI servers where low-privileged remote users log in, since exploitation requires an authorized account plus user interaction. Note that a public PoC exists, so monitor WMI-related process and event logs for anomalous activity until systems are patched.

Affected
Microsoft Windows (Windows Management Instrumentation / WMI component)
Estimated exposure
mass≈1 billion+ Windows endpoints (WMI is a core component on effectively all Windows clients and servers) — WMI ships with every Windows client and server installation, and Microsoft's widely cited install base of roughly 1.4 billion active Windows devices implies near-universal presence, though exploitation additionally requires an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.