Junglewise Threat Intelligence

CVE-2026-69337: Microsoft Windows Registry double free privilege escalation

CVE-2026-69337 · Severity: high · CVSS 7.1 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A memory management flaw in the Windows Registry can allow an authorized user on a network to gain higher system privileges. This could enable an attacker with legitimate access to take control of a Windows system and access sensitive data or disrupt critical operations.

Technical details

A double-free vulnerability exists in Windows Registry handling, where a memory region is freed twice during processing, potentially corrupting heap state. An authorized attacker on the network can trigger this condition to corrupt kernel memory and escalate privileges from a user context to SYSTEM or kernel level. The vulnerability requires prior authentication and network connectivity but does not require user interaction. Successful exploitation enables arbitrary code execution with elevated privileges. A patch from Microsoft Security Response Center is available.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats