ZeroHour

CVE-2026-69814

mass

Use-After-Free Privilege Escalation in Windows Credential Providers

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69814 is a use-after-free (CWE-416) memory-corruption flaw in Windows Credential Providers, the components that handle user authentication on Windows logon. An attacker who already has a low-privileged, authorized foothold on a machine can trigger the bug by exercising the credential-provider path, causing freed memory to be reused and corrupting the process without any user interaction. Successful exploitation elevates the attacker's privileges locally, with high potential impact to confidentiality, integrity, and availability on the compromised host (CVSS 7.0, high). Any Windows deployment is potentially affected, since credential providers ship with the operating system; Microsoft has not published specific affected version ranges in the available data. As of now there is no known public proof-of-concept, no CISA KEV listing, and only a low predicted exploitation probability (EPSS 0.3%).

What to do: Apply Microsoft's security update for CVE-2026-69814 through Windows Update as it rolls out, and confirm patch status against Microsoft's advisory for the exact Windows versions in your estate. Prioritize hosts where low-privileged or untrusted users can log on locally, such as shared workstations, terminal/RDS servers, and kiosk systems, and consider restricting local logon rights where possible to reduce exposure. No public PoC or in-the-wild exploitation is known, so routine patch cadence is reasonable absent further escalation.

Affected
Microsoft Windows Credential Providers (as shipped with Windows)
Estimated exposure
mass>1 billion Windows devices (Windows' global installed base) — Credential providers are a built-in component of Windows, so the plausible exposure is on the order of Windows' worldwide installed base of roughly a billion-plus devices, though actual exploitation risk is limited to hosts where untrusted…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Credential Providers allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.