Junglewise Threat Intelligence

CVE-2026-69401: Audio Video Control Transport Protocol use after free privilege escalation

CVE-2026-69401 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A use-after-free vulnerability exists in the Audio Video Control Transport Protocol (AVCTP), a component used for audio and video device control in Windows systems. An authorized local attacker can exploit this flaw to escalate their privileges on the affected system, potentially gaining full administrative control.

Technical details

The vulnerability is a use-after-free condition in the Audio Video Control Transport Protocol implementation. The flaw requires the attacker to be already authenticated on the system (local access with valid credentials). By exploiting this memory safety issue, an attacker can achieve privilege escalation from a standard user account to a higher privilege level. The vulnerability is tracked as CVE-2026-69401 with a CVSS score of 7.0, and no public exploits have been reported in the wild at this time.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats