CVE-2026-69682
nicheUse-After-Free Local Privilege Escalation in Microsoft Windows Host Guardian Service
CVE-2026-69682 is a use-after-free (CWE-416) caused by a race condition (CWE-362) in the Windows Host Guardian Service (HGS), a Microsoft Windows Server role used for guarded fabric attestation and Shielded VM key protection. To trigger it, an authorized attacker with low privileges on the local machine must win a timing race between operations — reflected in the high attack complexity (AC:H) of the CVSS score — with no user interaction required. A successful exploit lets the attacker elevate privileges locally, with high impact on confidentiality, integrity, and availability (effectively full local compromise of the HGS host). Only Windows systems with the Host Guardian Service role installed are affected; standard client and server systems without the role are not exposed to this flaw. There is no known exploitation, no public proof-of-concept, it is not in CISA KEV, and EPSS puts the 30-day exploitation probability at just 0.2% (5th percentile).
What to do: Apply Microsoft's security update for CVE-2026-69682 as soon as it is available in your patch channel, prioritizing servers where the Host Guardian Service role is installed. As an interim mitigation, limit interactive and remote local logon on HGS hosts to trusted administrators, since exploitation requires an authorized local account. Given the low EPSS score, absence of a public PoC, and no KEV listing, this can be handled within normal Patch Tuesday cycles unless your HGS servers are multi-user or high-value attestation infrastructure.
| Microsoft Windows Host Guardian Service (HGS) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Host Guardian Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-362, CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.