Junglewise Threat Intelligence

CVE-2026-69472: Microsoft Windows Devices Human Interface use-after-free privilege escalation

CVE-2026-69472 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

Windows Devices Human Interface is a core Windows component responsible for handling input devices and user interaction. A use-after-free memory vulnerability allows an attacker who already has local access to the system to escalate their privileges to a higher level, potentially gaining administrative control.

Technical details

A use-after-free vulnerability exists in the Windows Devices Human Interface component, where memory that has been deallocated is subsequently accessed, leading to potential code execution. The vulnerability requires an attacker to already have local access to the system or be an authorized user. The attack vector is local privilege escalation, where an authenticated attacker can exploit the flaw to gain elevated privileges. The CVSS score of 7.0 (high) reflects the significant impact of successful exploitation, though it requires local access as a precondition.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats