CVE-2026-69891
massUse-After-Free Local Privilege Escalation in Windows Media
CVE-2026-69891 is a use-after-free memory flaw (CWE-416) in the Windows Media component of Microsoft Windows. A local attacker who already holds valid low-privilege credentials on the system can trigger the flaw by getting the affected media component to access freed memory under specific conditions, and exploitation complexity is rated high. A successful exploit elevates the attacker's privileges locally, with high impact on the confidentiality, integrity, and availability of the host. All Windows installations carrying the affected Windows Media component are potentially exposed, though the flaw requires local authenticated access and is not remotely exploitable. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known; EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Consult Microsoft's security advisory for the affected Windows builds and apply the released security update through Windows Update, prioritizing multi-user hosts and workstations where untrusted or low-trust users can log on locally. Until patched, restrict local logon rights on sensitive machines to trusted accounts, since exploitation requires an authorized local user. With no public PoC, no KEV listing, and low EPSS, this can be handled in a normal patch cycle unless local access on high-value hosts is broadly shared.
| Microsoft Windows (Windows Media component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.