CVE-2026-69472
massUse-After-Free Local Privilege Escalation in Windows Human Interface Device (HID)
CVE-2026-69472 is a use-after-free memory corruption flaw (CWE-416) in the Windows Devices Human Interface component. A local attacker who is already authorized on the system (low privileges required, no user interaction) can trigger the flaw by causing the HID component to reference freed memory; the attack requires high complexity, meaning reliable exploitation is timing- or state-dependent. Successful exploitation allows the attacker to elevate privileges locally on the affected machine, gaining higher-level access than their starting account. Any Windows system with the standard HID component is affected; the affected build ranges are defined in Microsoft's advisory rather than in the data available here. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only 0.3% (19th percentile), so no active exploitation is known.
What to do: Apply Microsoft's security update for CVE-2026-69472 from the associated monthly release and verify the patched build against the versions listed in Microsoft's advisory. Prioritize systems where untrusted users hold local accounts — multi-user servers, RDS/VDI hosts, kiosks, and shared workstations — since the flaw requires local access. Given the high attack complexity, low EPSS, and absence of a known PoC, standard patch-cadence remediation is reasonable; no specific workaround is documented in the available data.
| Microsoft Windows (Devices Human Interface component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Devices Human Interface allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.