ZeroHour

CVE-2026-69652

mass

Use-After-Free Local Privilege Escalation in Microsoft Windows Win32K

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

Microsoft Windows' Win32K kernel component contains a use-after-free flaw (CWE-416) that an authorized local attacker with low privileges can trigger without user interaction, though the high complexity rating indicates exploitation depends on favorable memory-layout conditions. A successful exploit elevates the attacker from standard user rights to kernel-level privileges, yielding high impact on confidentiality, integrity, and availability through full system-level control. Any Windows system running the affected Win32K code is potentially exposed; the specific affected Windows versions and builds are not enumerated in the available data, so defenders should consult Microsoft's advisory for the definitive list. Exploitation status is currently quiet: there is no known public proof-of-concept, the CVE is not in CISA KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69652 through Windows Update / the monthly Patch Tuesday rollout once your build is confirmed affected against the advisory's version list. Prioritize systems where untrusted or low-privilege users can execute code locally, such as VDI hosts, RDS/session servers, shared workstations, and kiosks, since local privilege escalation there undermines user separation. With no known PoC or in-the-wild exploitation, this can follow normal patch cadence, but do not defer past the next patch cycle given the kernel-level impact.

Affected
Microsoft Windows (Win32K kernel component)
Estimated exposure
masshundreds of millions to 1 billion+ Windows installations plausibly affected (Win32K ships in every Windows client and server build) — Windows runs on well over a billion devices worldwide and the Win32K kernel driver is present on essentially all of them, although the affected version range is not enumerated in the available data, so this is an upper-bound estimate of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.