ZeroHour

CVE-2026-69473

mass

Use-After-Free Local Privilege Escalation in Microsoft Windows Kernel

CVSS 3.1
7.0 high
EPSS
<1%p19
Published
()
Modified
AI analysis

Microsoft's Windows Kernel contains a use-after-free vulnerability (CWE-416), a memory-corruption flaw in which the kernel references memory that has already been freed. The flaw is triggered locally by an authorized attacker who already has low-privileged code execution on the machine; no user interaction is required, though the attack complexity is rated high. Successful exploitation allows the attacker to elevate privileges on the local system, with high impact to confidentiality, integrity, and availability — effectively gaining kernel-level (SYSTEM-equivalent) control of the host. Any Windows system running a vulnerable kernel build is affected; the available data does not specify which Windows versions or branches are impacted, so defenders should check Microsoft's advisory for the affected build list. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.3% (19th percentile) probability of exploitation within 30 days, indicating no confirmed in-the-wild exploitation.

What to do: Check Microsoft's security advisory for the list of affected Windows builds and apply the kernel update via Windows Update as soon as it is released. Because this is a local privilege escalation rather than a remote flaw, prioritize hosts where untrusted or multiple users can run code locally — RDS/session servers, VDI images, and shared workstations — and ensure local users operate with least privilege in the interim. No public exploit or in-the-wild activity is known, so normal patch-cadence handling is reasonable for most environments.

Affected
Microsoft Windows Kernel
Estimated exposure
mass≈1 billion+ Windows installations (global Windows installed base) — Windows runs on an estimated 1.4+ billion active devices worldwide, and a kernel-local privilege-escalation flaw plausibly affects the bulk of the supported installed base, although the exact affected builds are not enumerated in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.