ZeroHour

CVE-2026-69606

mass

Use-After-Free Local Privilege Elevation in Microsoft Windows Shell

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69606 is a use-after-free memory-safety flaw (CWE-416) in the Windows Shell that permits local elevation of privilege. Exploitation is local (AV:L), requires the attacker to already hold authorized low-privileged access to the machine (PR:L), involves no user interaction (UI:N), and carries high attack complexity (AC:H), meaning reliable triggering depends on favorable memory-timing conditions rather than simple, repeatable input. A successful attacker gains elevated privileges beyond their authorized level on the local host, with the CVSS high confidentiality, integrity, and availability scores indicating the flaw can enable full local compromise. Any Windows system shipping the affected Windows Shell component is potentially affected, and the flaw is most consequential on machines where untrusted users or malware can obtain a low-privileged foothold, such as shared workstations, remote desktop/VDI hosts, and multi-user servers. As of this writing there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days (17th percentile), although local privilege-escalation bugs of this class are frequently chained with other flaws to complete an intrusion.

What to do: Deploy Microsoft's security update addressing CVE-2026-69606 as soon as it is available in your patch channel, checking Microsoft's advisory for the affected and fixed Windows builds. Prioritize multi-user and shared-access systems (RDS/VDI hosts, kiosk or shared workstations, servers where low-privileged users log on), since exploitation requires an existing local foothold. In the interim, restrict creation of local accounts, monitor for unexpected privilege escalation on endpoints, and note that no public PoC or in-the-wild exploitation is currently known.

Affected
Microsoft Windows Shell
Estimated exposure
mass~1 billion+ Windows devices (Windows Shell is a default component shipped with the OS) — Microsoft has publicly reported over 1.4 billion monthly active Windows 10/11 devices and the Windows Shell ships by default with Windows, so effectively the entire Windows installed base is plausibly affected, though exploitation requires…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.