ZeroHour

CVE-2026-69472

mass

Use-After-Free Local Privilege Escalation in Windows Human Interface Device (HID)

CVSS 3.1
7.0 high
EPSS
<1%p19
Published
()
Modified
AI analysis

CVE-2026-69472 is a use-after-free memory corruption flaw (CWE-416) in the Windows Devices Human Interface component. A local attacker who is already authorized on the system (low privileges required, no user interaction) can trigger the flaw by causing the HID component to reference freed memory; the attack requires high complexity, meaning reliable exploitation is timing- or state-dependent. Successful exploitation allows the attacker to elevate privileges locally on the affected machine, gaining higher-level access than their starting account. Any Windows system with the standard HID component is affected; the affected build ranges are defined in Microsoft's advisory rather than in the data available here. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at only 0.3% (19th percentile), so no active exploitation is known.

What to do: Apply Microsoft's security update for CVE-2026-69472 from the associated monthly release and verify the patched build against the versions listed in Microsoft's advisory. Prioritize systems where untrusted users hold local accounts — multi-user servers, RDS/VDI hosts, kiosks, and shared workstations — since the flaw requires local access. Given the high attack complexity, low EPSS, and absence of a known PoC, standard patch-cadence remediation is reasonable; no specific workaround is documented in the available data.

Affected
Microsoft Windows (Devices Human Interface component)
Estimated exposure
mass≈1 billion+ Windows installations (HID stack ships as a standard Windows component) — The Human Interface Device component is present in the default Windows client and server installs, so the realistic exposure ceiling is the global Windows installed base, though exploitation requires a low-privileged local user rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Devices Human Interface allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.