CVE-2026-69605
massUse-After-Free Local Privilege Escalation in Microsoft Install Service
CVE-2026-69605 is a use-after-free memory-safety flaw (CWE-416) in the Microsoft Install Service, the Windows component that handles software install requests. A local attacker who already holds limited (low-privilege) access on a machine can trigger the condition through the service's handling of install operations; exploitation requires no user interaction, though it carries high attack complexity. Successful exploitation elevates the attacker's privileges to the local administrator/SYSTEM level, granting full control over the device's confidentiality, integrity, and availability. Any Windows system running the Install Service is affected, but exploitation presupposes an attacker who can already execute code locally on the target. There is currently no known public proof of concept, no CISA KEV listing, and EPSS assigns only a 0.3% probability of exploitation within 30 days, so no active exploitation is known.
What to do: Apply the Windows security update that remediates the Install Service, checking Microsoft's advisory for the specific Windows versions in your estate; prioritize multi-user systems, servers accepting interactive logons, and VDI/kiosk hosts where low-privilege users are untrusted. Interim mitigation is limited to restricting local logon to trusted users on sensitive systems. Given the low EPSS (0.3%), absence of KEV listing, and no known public PoC, most organizations can address this within their regular patch cycle.
| Microsoft Install Service (Windows component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Microsoft Install Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.