CVE-2026-69500
massUse-After-Free Local Privilege Escalation in Windows Image Acquisition
CVE-2026-69500 is a use-after-free vulnerability (CWE-416) in Windows Image Acquisition (WIA), the built-in Windows service that handles communication with imaging devices such as scanners and cameras. An attacker who already has authorized low-privileged access on a local machine can trigger the flaw by interacting with the WIA service; the vulnerability requires high attack complexity but no user interaction. Successful exploitation allows the attacker to elevate privileges locally, gaining high impact on the confidentiality, integrity, and availability of the affected system. All Windows installations that include the affected WIA component are potentially exposed, though an attacker must already be able to execute code locally. There is currently no known exploitation: the flaw is not in CISA's KEV catalog, has no public proof-of-concept, and carries a low 0.3% EPSS probability of exploitation within 30 days.
What to do: Monitor for and apply Microsoft's security update for CVE-2026-69500 through Windows Update as soon as it is released, and verify your installed builds against Microsoft's advisory for the exact fixed versions. Until patched, prioritize systems where untrusted or low-privileged users can run code locally (shared workstations, kiosks, multi-user servers), since the flaw requires local access. No workaround is documented; no public exploit or in-the-wild exploitation is known at this time.
| Microsoft Windows Image Acquisition (WIA) component of Microsoft Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.