ZeroHour

CVE-2026-69891

mass

Use-After-Free Local Privilege Escalation in Windows Media

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69891 is a use-after-free memory flaw (CWE-416) in the Windows Media component of Microsoft Windows. A local attacker who already holds valid low-privilege credentials on the system can trigger the flaw by getting the affected media component to access freed memory under specific conditions, and exploitation complexity is rated high. A successful exploit elevates the attacker's privileges locally, with high impact on the confidentiality, integrity, and availability of the host. All Windows installations carrying the affected Windows Media component are potentially exposed, though the flaw requires local authenticated access and is not remotely exploitable. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known; EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Consult Microsoft's security advisory for the affected Windows builds and apply the released security update through Windows Update, prioritizing multi-user hosts and workstations where untrusted or low-trust users can log on locally. Until patched, restrict local logon rights on sensitive machines to trusted accounts, since exploitation requires an authorized local user. With no public PoC, no KEV listing, and low EPSS, this can be handled in a normal patch cycle unless local access on high-value hosts is broadly shared.

Affected
Microsoft Windows (Windows Media component)
Estimated exposure
mass≈1 billion+ Windows devices (Windows Media ships with the OS; actual vulnerable builds depend on the advisory's version list) — Windows Media is a built-in Windows component and Windows' active install base is on the order of 1–1.5 billion devices, so the potentially affected population is in the hundreds of millions or more, though exploitation requires local…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.