ZeroHour

CVE-2026-69654

mass

Use-After-Free Local Privilege Escalation in Microsoft Windows Accounts Control

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69654 is a use-after-free memory corruption flaw (CWE-416) in the Windows Accounts Control component of Microsoft Windows. It can be triggered by an attacker who already holds authorized, low-privileged access on the local machine; the high attack complexity in the CVSS vector indicates exploitation depends on favorable runtime conditions, although no user interaction is required. Successful exploitation yields local privilege elevation, giving the attacker highly impactful read, write, and execution capabilities in a more privileged context. Any Windows system running an affected build is potentially exposed, but only to attackers or malware that can already execute limited code locally — the flaw is not remotely exploitable on its own. There is currently no public proof-of-concept, no entry in CISA's Known Exploited Vulnerabilities catalog, and a low 0.3% EPSS probability of exploitation within 30 days, indicating no known exploitation to date.

What to do: Apply Microsoft's security update for CVE-2026-69654 as soon as it is published, prioritizing multi-user hosts such as terminal/RDS servers, shared workstations, and endpoints where untrusted code runs under low-privileged accounts. Until patched, restrict local account creation and execution of untrusted code by unprivileged users to reduce exposure. Check Microsoft's advisory to determine which Windows builds are affected, as version details are not yet specified in the available data.

Affected
Microsoft Windows (Accounts Control component)
Estimated exposure
masson the order of 100M–1B+ Windows devices potentially affected (exact scope unknown pending Microsoft's affected-build list) — The global Windows install base exceeds one billion devices and the Accounts Control component ships as part of Windows, so even a subset of affected builds plausibly leaves hundreds of millions of systems exposed — a rough estimate, since…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.