CVE-2026-69613
massUse-After-Free Local Privilege Escalation in Windows Image Acquisition
CVE-2026-69613 is a use-after-free memory-safety flaw (CWE-416) in Windows Image Acquisition (WIA), the Windows component that handles image capture from scanners and cameras. An attacker who already has a low-privileged authorized foothold on a local machine can trigger the flaw by interacting with the WIA component, and the high attack complexity of the CVSS vector suggests successful exploitation is timing- or state-dependent rather than trivially reliable. A successful exploit allows the attacker to elevate privileges on the local system with no user interaction required. Any Windows deployment containing the affected WIA component is potentially exposed, though specific affected builds are not enumerated in the available data. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at just 0.3% (17th percentile), indicating no confirmed in-the-wild exploitation.
What to do: Apply Microsoft's security update for CVE-2026-69613 as soon as it is released via Windows Update, and check Microsoft's advisory for the definitive list of affected builds before scoping. Prioritize patching multi-user Windows hosts, VDI/terminal servers, kiosks, and workstations where untrusted or low-privileged users can log in and run code, since exploitation requires local access rather than network reachability. No workarounds are documented in the available data; standard least-privilege controls on local accounts reduce the value of a successful elevation.
| Microsoft Windows (Windows Image Acquisition component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.