ZeroHour

CVE-2026-69605

mass

Use-After-Free Local Privilege Escalation in Microsoft Install Service

CVSS 3.1
7.0 high
EPSS
<1%p20
Published
()
Modified
AI analysis

CVE-2026-69605 is a use-after-free memory-safety flaw (CWE-416) in the Microsoft Install Service, the Windows component that handles software install requests. A local attacker who already holds limited (low-privilege) access on a machine can trigger the condition through the service's handling of install operations; exploitation requires no user interaction, though it carries high attack complexity. Successful exploitation elevates the attacker's privileges to the local administrator/SYSTEM level, granting full control over the device's confidentiality, integrity, and availability. Any Windows system running the Install Service is affected, but exploitation presupposes an attacker who can already execute code locally on the target. There is currently no known public proof of concept, no CISA KEV listing, and EPSS assigns only a 0.3% probability of exploitation within 30 days, so no active exploitation is known.

What to do: Apply the Windows security update that remediates the Install Service, checking Microsoft's advisory for the specific Windows versions in your estate; prioritize multi-user systems, servers accepting interactive logons, and VDI/kiosk hosts where low-privilege users are untrusted. Interim mitigation is limited to restricting local logon to trusted users on sensitive systems. Given the low EPSS (0.3%), absence of KEV listing, and no known public PoC, most organizations can address this within their regular patch cycle.

Affected
Microsoft Install Service (Windows component)
Estimated exposure
massorder of hundreds of millions of Windows devices (Install Service ships built-in with Windows; >1 billion Windows devices worldwide) — The Install Service is a built-in Windows component, so exposure scales with the installed base of Windows (on the order of a billion devices), though only machines where untrusted low-privilege users can run code are realistically…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.