CVE-2026-69816
massUse-After-Free Local Privilege Escalation in Microsoft Windows Accounts Control
CVE-2026-69816 is a use-after-free vulnerability (CWE-416) in the Windows Accounts Control component of Microsoft Windows. An attacker who already has low privileges and can execute code locally can trigger the flaw — memory that has been freed is subsequently accessed — and the attack requires no user interaction, though its high attack complexity makes reliable exploitation harder. Successful exploitation elevates the attacker's privileges on the local machine, with high impact on confidentiality, integrity, and availability. Affected scope includes Windows systems carrying the Accounts Control component; the available data does not specify affected version ranges, so defenders should consult Microsoft's MSRC advisory for the exact list. There is no known public proof-of-concept, no reports of in-the-wild exploitation, and the flaw is not in CISA's KEV, with EPSS estimating only a 0.3% probability of exploitation in the next 30 days.
What to do: Install the Windows security update addressing CVE-2026-69816 via Windows Update as soon as Microsoft releases it, and check the MSRC advisory for the definitive affected-version list. Until patched, prioritize hosts where untrusted or low-privilege users have local access (shared workstations, multi-user systems, VDI) and watch for local privilege-escalation activity. Because this is a local-only privilege escalation most useful as a second stage after initial access, standard endpoint hygiene and timely patching materially limit practical risk.
| Microsoft Windows (Accounts Control component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.