Junglewise Threat Intelligence

CVE-2026-69654: Microsoft Windows Accounts Control use-after-free

CVE-2026-69654 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Accounts Control is a system component that manages user account permissions and access controls in Windows. A use-after-free flaw allows an authorized local user to execute code with elevated system privileges, potentially gaining full control of the computer.

Technical details

A use-after-free vulnerability exists in Windows Accounts Control, a core Windows system component. The vulnerability allows an authenticated local attacker to escalate privileges by exploiting improper memory management within the affected component. The attack requires local access and existing user account authorization. Successful exploitation enables arbitrary code execution with system-level privileges. Microsoft has released patches to remediate this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats