CVE-2026-69470
massUse-after-free privilege escalation in Windows Connected User Experiences and Telemetry
CVE-2026-69470 is a use-after-free memory-safety flaw (CWE-416) in the Windows Connected User Experiences and Telemetry component, the built-in telemetry service (commonly known as DiagTrack) that ships and runs by default on Windows. An attacker who already holds a low-privileged account on the machine (an 'authorized attacker') can trigger the flaw through that component, and, because attack complexity is rated high, successful exploitation is not guaranteed but would yield code execution with elevated (typically SYSTEM-level) privileges on the host. As a local privilege-escalation bug, it is most dangerous as a second stage of an attack, letting a standard user or malware foothold break out to full system rights. Any Windows system carrying the component is potentially affected, though the specific affected Windows version ranges are only in Microsoft's advisory and are not specified in the available data. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only about a 0.3% chance of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69470 via Windows Update as part of routine patching, prioritizing machines where untrusted or standard users can log on interactively such as end-user workstations, shared machines, and RDS/terminal servers. Check Microsoft's advisory for the exact affected builds and confirm the telemetry component is patched; until then, restricting interactive logon to trusted users reduces practical exposure. No emergency response is warranted given no known exploitation, high attack complexity, and low EPSS.
| Microsoft Windows Connected User Experiences and Telemetry component (DiagTrack service) in Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.