Junglewise Threat Intelligence

CVE-2026-69324: Microsoft Windows Performance Monitor type confusion privilege escalation

CVE-2026-69324 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Performance Monitor is a system tool used to monitor computer performance and resource usage. A type confusion vulnerability in this component allows an authorized user on a Windows system to elevate their privileges to a higher level, potentially gaining full system control.

Technical details

The vulnerability is a type confusion flaw in Windows Performance Monitor that occurs when the application accesses a resource using an incompatible type. An authorized attacker with local access can exploit this type safety violation to achieve local privilege escalation. The attack requires the attacker to already have authentication/local access to the system. Microsoft has published a security update to address this issue.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats