Junglewise Threat Intelligence

CVE-2026-69341: Microsoft Windows Image Acquisition use-after-free privilege escalation

CVE-2026-69341 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Image Acquisition is a system component that enables applications to communicate with image capture devices such as scanners and cameras. A use-after-free vulnerability in this component allows an authorized local user to execute code with elevated system privileges, potentially leading to full system compromise or malware installation.

Technical details

A use-after-free vulnerability exists in Windows Image Acquisition, a system library component that handles interaction with imaging devices. The vulnerability allows an authenticated local attacker to trigger reuse of freed memory, resulting in arbitrary code execution with elevated privileges. This requires the attacker to already have local access to the system. Microsoft has released a security update to address this vulnerability.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats