Junglewise Threat Intelligence

CVE-2026-69613: Microsoft Windows Image Acquisition use after free privilege escalation

CVE-2026-69613 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Image Acquisition is a built-in Windows component used to manage and acquire images from cameras and scanners. A use-after-free memory flaw allows an authorized local attacker to escalate their privileges to a higher level of system access, potentially enabling unauthorized administrative control over the computer.

Technical details

A use-after-free vulnerability exists in Windows Image Acquisition, a system component responsible for handling image acquisition operations. An authorized local attacker can trigger the flaw by providing specially crafted input to the component, causing it to reference memory that has been freed. This allows execution of arbitrary code in the context of the affected process. Exploitation requires local access and prior authorization on the system. A patch is available from Microsoft.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats