ZeroHour

CVE-2026-69500

mass

Use-After-Free Local Privilege Escalation in Windows Image Acquisition

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69500 is a use-after-free vulnerability (CWE-416) in Windows Image Acquisition (WIA), the built-in Windows service that handles communication with imaging devices such as scanners and cameras. An attacker who already has authorized low-privileged access on a local machine can trigger the flaw by interacting with the WIA service; the vulnerability requires high attack complexity but no user interaction. Successful exploitation allows the attacker to elevate privileges locally, gaining high impact on the confidentiality, integrity, and availability of the affected system. All Windows installations that include the affected WIA component are potentially exposed, though an attacker must already be able to execute code locally. There is currently no known exploitation: the flaw is not in CISA's KEV catalog, has no public proof-of-concept, and carries a low 0.3% EPSS probability of exploitation within 30 days.

What to do: Monitor for and apply Microsoft's security update for CVE-2026-69500 through Windows Update as soon as it is released, and verify your installed builds against Microsoft's advisory for the exact fixed versions. Until patched, prioritize systems where untrusted or low-privileged users can run code locally (shared workstations, kiosks, multi-user servers), since the flaw requires local access. No workaround is documented; no public exploit or in-the-wild exploitation is known at this time.

Affected
Microsoft Windows Image Acquisition (WIA) component of Microsoft Windows
Estimated exposure
masshundreds of millions to >1 billion Windows installations (WIA ships as a built-in Windows component) — WIA is a default component of the Windows client operating system, and Windows runs on well over a billion devices worldwide, so the potential installed base is mass-scale even though exploitation requires an existing local attacker.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.