ZeroHour

CVE-2026-69470

mass

Use-after-free privilege escalation in Windows Connected User Experiences and Telemetry

CVSS 3.1
7.0 high
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2026-69470 is a use-after-free memory-safety flaw (CWE-416) in the Windows Connected User Experiences and Telemetry component, the built-in telemetry service (commonly known as DiagTrack) that ships and runs by default on Windows. An attacker who already holds a low-privileged account on the machine (an 'authorized attacker') can trigger the flaw through that component, and, because attack complexity is rated high, successful exploitation is not guaranteed but would yield code execution with elevated (typically SYSTEM-level) privileges on the host. As a local privilege-escalation bug, it is most dangerous as a second stage of an attack, letting a standard user or malware foothold break out to full system rights. Any Windows system carrying the component is potentially affected, though the specific affected Windows version ranges are only in Microsoft's advisory and are not specified in the available data. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only about a 0.3% chance of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69470 via Windows Update as part of routine patching, prioritizing machines where untrusted or standard users can log on interactively such as end-user workstations, shared machines, and RDS/terminal servers. Check Microsoft's advisory for the exact affected builds and confirm the telemetry component is patched; until then, restricting interactive logon to trusted users reduces practical exposure. No emergency response is warranted given no known exploitation, high attack complexity, and low EPSS.

Affected
Microsoft Windows Connected User Experiences and Telemetry component (DiagTrack service) in Windows
Estimated exposure
mass~1 billion+ Windows installations (component runs by default on Windows 10/11) — The Connected User Experiences and Telemetry (DiagTrack) service is installed and enabled by default on modern Windows client and server editions, which collectively run on well over a billion devices, so potential exposure is effectively…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.