CVE-2026-69890
massUse-After-Free Local Privilege Escalation in Windows Virtual Trusted Platform Module
CVE-2026-69890 is a use-after-free (CWE-416) in the Windows Virtual Trusted Platform Module (vTPM), the software TPM component Microsoft ships as part of Windows virtualization. A local attacker who is already authorized on the system (the CVSS vector requires high privileges) can trigger the flaw by interacting with the vTPM in a way that causes memory to be freed and then reused, corrupting state beyond the original security scope. Successful exploitation elevates the attacker's privileges locally, and the CVSS scope-changed metric (S:C) indicates the impact crosses a security boundary, which for a vTPM component plausibly means the guest/TPM trust boundary rather than only the calling process. Affected parties are organizations and users running Windows deployments where the vTPM component is present, notably virtualization hosts and environments relying on virtual TPM and virtualization-based security. There is currently no evidence of exploitation: the flaw is not in CISA KEV, has no known public proof-of-concept, and carries a low EPSS score of 0.3% (17th percentile).
What to do: Apply Microsoft's security update for CVE-2026-69890 via Windows Update/WSUS as soon as it is available, prioritizing Hyper-V hosts and other systems where vTPM-backed VMs or virtualization-based security are in use. Until patching, limit local administrative access on those hosts and review VM/TPM configurations for unnecessary exposure. Check Microsoft's advisory for the definitive list of affected Windows versions, since version ranges were not included in the source data.
| Microsoft Windows Virtual Trusted Platform Module (vTPM) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.