ZeroHour

CVE-2026-69576

mass

Use-after-free privilege escalation in Microsoft Windows Graphic Fonts

CVSS 3.1
7.8 high
EPSS
<1%p23
Published
()
Modified
AI analysis

CVE-2026-69576 is a use-after-free vulnerability (CWE-416) in the Graphic Fonts component of Microsoft Windows, addressed in Microsoft's September 2026 Patch Tuesday release. An attacker who already has authorized, limited local access to a system can trigger improper memory reuse during font handling, and no user interaction is required. Successful exploitation elevates the attacker's privileges locally, with high impact on confidentiality, integrity, and availability on the compromised host (CVSS 3.1 base score 7.8). Any organization running Windows is potentially affected, but exploitation requires local execution, so internet-facing attack surface is limited. There is currently no evidence of exploitation in the wild: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Apply Microsoft's September 2026 security updates to all Windows endpoints as soon as practical, prioritizing multi-user systems such as RDS/VDI hosts and shared workstations where low-privileged local accounts are available to untrusted users. Since exploitation requires local access, keep standard-user rights minimal and verify patch levels through WSUS/Intune/SCCM compliance reports. No public PoC or in-the-wild exploitation is known, but track this CVE in routine patch-compliance reporting.

Affected
Microsoft Windows (Graphic Fonts component)
Estimated exposure
mass~1 billion+ Windows devices (global Windows installed base; any system granting local logon is in scope) — Windows runs on more than a billion devices worldwide and a use-after-free in a core graphics/font component is present in broadly deployed builds, though realistic exposure is limited to systems where untrusted users hold local accounts.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Graphic Fonts allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1