Junglewise Threat Intelligence

CVE-2026-69605: Microsoft Install Service use-after-free privilege escalation

CVE-2026-69605 · Severity: high · CVSS 7 · Published 2026-09-08

Vendors: Microsoft.

Executive brief

Microsoft Install Service is a Windows system component responsible for managing software installation and updates. A use-after-free memory vulnerability in this service allows an authorized local user to elevate their privileges to system level, potentially enabling full control over the affected computer and access to all data and services running on it.

Technical details

A use-after-free vulnerability exists in Microsoft Install Service where memory is accessed after being freed, leading to memory corruption. The vulnerability requires an authenticated local attacker to trigger the flaw through local code execution. Successful exploitation results in privilege escalation from user-level to system-level permissions. The attack vector is local and requires authorization (valid user account on the system). Microsoft has issued a security update to address this vulnerability; patching is recommended for all affected systems.

Affected products

  • Microsoft Install Service <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References