CVE-2026-69654
massUse-After-Free Local Privilege Escalation in Microsoft Windows Accounts Control
CVE-2026-69654 is a use-after-free memory corruption flaw (CWE-416) in the Windows Accounts Control component of Microsoft Windows. It can be triggered by an attacker who already holds authorized, low-privileged access on the local machine; the high attack complexity in the CVSS vector indicates exploitation depends on favorable runtime conditions, although no user interaction is required. Successful exploitation yields local privilege elevation, giving the attacker highly impactful read, write, and execution capabilities in a more privileged context. Any Windows system running an affected build is potentially exposed, but only to attackers or malware that can already execute limited code locally — the flaw is not remotely exploitable on its own. There is currently no public proof-of-concept, no entry in CISA's Known Exploited Vulnerabilities catalog, and a low 0.3% EPSS probability of exploitation within 30 days, indicating no known exploitation to date.
What to do: Apply Microsoft's security update for CVE-2026-69654 as soon as it is published, prioritizing multi-user hosts such as terminal/RDS servers, shared workstations, and endpoints where untrusted code runs under low-privileged accounts. Until patched, restrict local account creation and execution of untrusted code by unprivileged users to reduce exposure. Check Microsoft's advisory to determine which Windows builds are affected, as version details are not yet specified in the available data.
| Microsoft Windows (Accounts Control component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.