ZeroHour

CVE-2026-69757

mass

Use-after-free privilege escalation in Microsoft Windows TCP/IP

CVSS 3.1
7.1 high
EPSS
<1%p49
Published
()
Modified
AI analysis

CVE-2026-69757 is a use-after-free (CWE-416) vulnerability in the Microsoft Windows TCP/IP stack. It can be triggered over the network by an authorized (low-privileged) attacker, but exploitation involves high attack complexity and requires user interaction, so it is not a trivially wormable remote flaw. A successful exploit allows the attacker to elevate privileges on the target Windows system, with high impact to confidentiality, integrity, and availability. Any Windows system whose TCP/IP stack is reachable by a low-privileged network user is potentially affected; the available data does not specify particular version ranges, and Microsoft (the CNA) is the authoritative source for the affected-version list. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.7% probability of exploitation within 30 days (49th percentile), indicating no known exploitation.

What to do: Monitor Microsoft's Security Update Guide and Windows Update/WSUS for the CVE-2026-69757 advisory and apply Microsoft's patch to affected Windows systems as soon as it is released, prioritizing multi-user servers and hosts reachable by untrusted, low-privileged users. Until patched, restrict untrusted network access to sensitive Windows hosts and review which low-privileged accounts can reach them. No public exploit or in-the-wild exploitation is known, so routine patch-cadence handling is currently reasonable.

Affected
Microsoft Windows TCP/IP (Windows operating systems)
Estimated exposure
mass≈1 billion+ Windows devices (TCP/IP stack present in essentially every Windows installation) — Windows runs on roughly 1–1.5 billion active devices worldwide and its TCP/IP stack is enabled on effectively all of them, though actual exploitability is narrower because the attack requires an authenticated low-privileged foothold and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.