ZeroHour

CVE-2026-69896

mass

Use-After-Free Local Privilege Escalation in Microsoft Windows Error Reporting

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69896 is a use-after-free (CWE-416) in Windows Error Reporting (WER), a built-in Microsoft Windows component. A local attacker who is already authorized on the system (low privileges) can trigger the flaw to execute code in the context of a more privileged process; the high attack complexity (AC:H) means reliable exploitation may depend on favorable memory layout or timing, but no user interaction is required. Successful exploitation yields local privilege elevation with high impact on confidentiality, integrity, and availability on the compromised host, earning a CVSS 3.1 base score of 7.0 (high). Any Windows system running the WER component is potentially affected; the source data does not specify which Windows versions or builds are vulnerable, so the Microsoft advisory should be consulted for the definitive affected-product list. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days (17th percentile).

What to do: Monitor Microsoft's security advisory for this CVE and apply the released security updates for affected Windows releases as soon as they are available. Because exploitation requires local code execution, prioritize patching shared workstations, terminal servers, and other systems where low-privileged or untrusted users can sign in. With no public PoC, no KEV listing, and a low EPSS score, routine patching cadence is acceptable for single-user or well-controlled endpoints.

Affected
Microsoft Windows (Windows Error Reporting component)
Estimated exposure
mass≈1 billion+ Windows endpoints (WER ships by default on essentially all Windows installations) — Windows Error Reporting is a default component of the Windows operating system, so the exposed population is effectively the entire Windows installed base — over a billion active devices — although the flaw is only exploitable by a local…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.