CVE-2026-69761
massUse-After-Free in Windows TCP/IP Enables Network Privilege Escalation
CVE-2026-69761 is a use-after-free (CWE-416) memory-corruption flaw in the Windows TCP/IP network stack that Microsoft rated high severity (CVSS 7.1). An attacker who already holds a low-privileged, authorized (authenticated) account can send network traffic that triggers the flawed memory handling and elevates their privileges on the target Windows host; per the CVSS vector, exploitation requires high attack complexity and some user interaction, but no unauthenticated access. Successful exploitation yields high impact to confidentiality, integrity, and availability, effectively giving the attacker elevated rights on the machine. Any organization running affected Microsoft Windows client or server releases is potentially exposed, with internet-facing or multi-user Windows systems the most attractive targets. As of this analysis there is no known public proof-of-concept, the CVE is not in the CISA KEV catalog, and EPSS puts 30-day exploitation probability at only 0.5% (43rd percentile), indicating no observed exploitation activity yet.
What to do: Install the Microsoft Windows security update that addresses CVE-2026-69761 as soon as it is available in the corresponding Patch Tuesday release, prioritizing internet-facing, multi-user, and jump/terminal Windows servers. Until patching is complete, limit authenticated remote access (e.g., restrict RDP and low-privileged network logons to trusted users) and monitor for anomalous privilege changes on Windows hosts. Refer to Microsoft's advisory for the exact affected and fixed Windows builds in your estate.
| Microsoft Windows (TCP/IP network stack) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.