Junglewise Threat Intelligence

CVE-2026-69573: Microsoft Windows UDFS use-after-free privilege escalation

CVE-2026-69573 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A use-after-free vulnerability in Windows' Universal Disk Format (UDF) file system driver allows an authorized local user to execute arbitrary code with elevated privileges. This could enable an attacker with existing system access to gain administrative control, compromising system integrity and potentially exposing sensitive data.

Technical details

The vulnerability is a use-after-free flaw in the Windows Universal Disk Format File System Driver (UDFS). An authenticated local attacker can trigger the use-after-free condition to escalate privileges. The attack requires local access to the system. Successful exploitation allows elevation of privileges, potentially leading to arbitrary code execution in the kernel context. A patch is available from Microsoft.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats