ZeroHour

CVE-2026-69735

mass

Use-After-Free Privilege Escalation in Windows Broadcast DVR User Service

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69735 is a use-after-free memory corruption flaw (CWE-416) in the Windows Broadcast DVR User Service. An attacker who already has valid low-privileged access to a local machine can trigger the flaw without user interaction, though the high attack-complexity rating suggests reliable exploitation requires favorable memory conditions. Successful exploitation lets the attacker elevate privileges to a higher local privilege level with full confidentiality, integrity, and availability impact on the host. Any Windows system running the affected Broadcast DVR User Service component is affected, with exposure concentrated on endpoints where untrusted users or malware already run locally. As of this analysis there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns it only a 0.3% chance of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69735 via Windows Update as soon as it is available, prioritizing shared hosts, terminal servers, and workstations where untrusted users or untrusted code run locally. Until patched, restrict local logon and interactive access on sensitive systems and monitor for anomalous local privilege escalation. Consult Microsoft's advisory for the exact affected Windows versions and KBs, since they are not listed in the summary data.

Affected
Microsoft Windows (Broadcast DVR User Service component)
Estimated exposure
massplausibly hundreds of millions of Windows endpoints ship the affected service component — Windows runs on well over a billion devices worldwide and the Broadcast DVR User Service is a standard Windows client component, so the potential installed base is on the order of hundreds of millions of machines, though only systems where…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.