Junglewise Threat Intelligence

CVE-2026-69567: Microsoft Windows NTFS use-after-free privilege escalation

CVE-2026-69567 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows NTFS, the file system used by Windows servers and workstations, contains a use-after-free vulnerability that allows a user with local access to escalate their privileges to administrator-level access. An attacker exploiting this bug could gain complete control over an affected system, including the ability to access sensitive data, install malware, or disrupt business operations.

Technical details

A use-after-free vulnerability exists in the Windows NTFS file system implementation, where memory is accessed after it has been freed, potentially leading to privilege escalation. The vulnerability requires an authenticated local attacker with existing user-level access to the system. By crafting specific NTFS operations or malformed file system structures, an attacker can trigger the use-after-free condition and execute arbitrary code in kernel context, achieving local privilege escalation to SYSTEM or administrator level. A patch has been released by Microsoft and should be applied promptly to affected systems.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats