ZeroHour

CVE-2026-69890

mass

Use-After-Free Local Privilege Escalation in Windows Virtual Trusted Platform Module

CVSS 3.1
7.5 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69890 is a use-after-free (CWE-416) in the Windows Virtual Trusted Platform Module (vTPM), the software TPM component Microsoft ships as part of Windows virtualization. A local attacker who is already authorized on the system (the CVSS vector requires high privileges) can trigger the flaw by interacting with the vTPM in a way that causes memory to be freed and then reused, corrupting state beyond the original security scope. Successful exploitation elevates the attacker's privileges locally, and the CVSS scope-changed metric (S:C) indicates the impact crosses a security boundary, which for a vTPM component plausibly means the guest/TPM trust boundary rather than only the calling process. Affected parties are organizations and users running Windows deployments where the vTPM component is present, notably virtualization hosts and environments relying on virtual TPM and virtualization-based security. There is currently no evidence of exploitation: the flaw is not in CISA KEV, has no known public proof-of-concept, and carries a low EPSS score of 0.3% (17th percentile).

What to do: Apply Microsoft's security update for CVE-2026-69890 via Windows Update/WSUS as soon as it is available, prioritizing Hyper-V hosts and other systems where vTPM-backed VMs or virtualization-based security are in use. Until patching, limit local administrative access on those hosts and review VM/TPM configurations for unnecessary exposure. Check Microsoft's advisory for the definitive list of affected Windows versions, since version ranges were not included in the source data.

Affected
Microsoft Windows Virtual Trusted Platform Module (vTPM)
Estimated exposure
masshundreds of millions of Windows systems ship the vTPM component, with the practically reachable surface concentrated on virtualization hosts (order of… — The vTPM component is part of the Windows client and server platform used across an install base of roughly a billion-plus devices, so while the reachable subset (hosts running vTPM-enabled VMs or VBS workloads) is smaller, the component's…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.