Junglewise Threat Intelligence

CVE-2026-69576: Microsoft Graphic Fonts use-after-free privilege escalation

CVE-2026-69576 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A use-after-free vulnerability in the Graphic Fonts component of Microsoft Windows allows an authenticated attacker with local system access to execute arbitrary code with elevated privileges. An attacker could exploit this flaw to gain administrator-level control over a compromised system, enabling them to install malware, steal data, or cause widespread damage.

Technical details

The vulnerability is a use-after-free condition in the Graphic Fonts component, a core Windows font rendering subsystem. The flaw requires local system access and authentication; an attacker cannot exploit it remotely over a network. By carefully crafting font data or triggering specific font processing operations, an attacker can corrupt memory and execute arbitrary code in the kernel or high-privilege process context. Microsoft has issued patches through standard security updates; administrators should apply these immediately to affected Windows systems.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats