CVE-2026-69735
massUse-After-Free Privilege Escalation in Windows Broadcast DVR User Service
CVE-2026-69735 is a use-after-free memory corruption flaw (CWE-416) in the Windows Broadcast DVR User Service. An attacker who already has valid low-privileged access to a local machine can trigger the flaw without user interaction, though the high attack-complexity rating suggests reliable exploitation requires favorable memory conditions. Successful exploitation lets the attacker elevate privileges to a higher local privilege level with full confidentiality, integrity, and availability impact on the host. Any Windows system running the affected Broadcast DVR User Service component is affected, with exposure concentrated on endpoints where untrusted users or malware already run locally. As of this analysis there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns it only a 0.3% chance of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69735 via Windows Update as soon as it is available, prioritizing shared hosts, terminal servers, and workstations where untrusted users or untrusted code run locally. Until patched, restrict local logon and interactive access on sensitive systems and monitor for anomalous local privilege escalation. Consult Microsoft's advisory for the exact affected Windows versions and KBs, since they are not listed in the summary data.
| Microsoft Windows (Broadcast DVR User Service component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.