ZeroHour

CVE-2026-69708

mass

Use-After-Free in Windows Web Platform Storage Enables Local Privilege Elevation

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69708 is a use-after-free (CWE-416) memory-safety flaw in the Windows Web Platform Storage component, reported by Microsoft. An attacker who already holds low privileges on a local system can trigger the flaw without user interaction, though the high attack complexity (CVSS AC:H) means reliable exploitation is more difficult than in typical local elevation bugs. Successful exploitation results in local privilege elevation, allowing the attacker to run code with elevated rights and gaining high impact on the confidentiality, integrity, and availability of the host. Any Windows deployment that includes the Web Platform Storage component is potentially affected; exact version ranges are not specified in the available data and should be confirmed against Microsoft's advisory. Exploitation status is quiet: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.

What to do: Apply the Microsoft security update for CVE-2026-69708 via Windows Update as soon as it is published, and verify affected version ranges against Microsoft's advisory. Until patched, restrict low-privileged local accounts on sensitive hosts and monitor Microsoft channels for updated guidance; no public PoC or in-the-wild exploitation is currently known, so urgent exposure is limited.

Affected
Microsoft Windows (Web Platform Storage component)
Estimated exposure
mass1M+ Windows installations plausibly affected (Windows installed base exceeds 1 billion devices) — Windows runs on well over a billion devices worldwide, so the potential install base is enormous, although the prevalence of the Web Platform Storage component specifically is not quantified in the available data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Web Platform Storage allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.