Junglewise Threat Intelligence

CVE-2026-69708: Microsoft Windows Web Platform Storage use-after-free privilege escalation

CVE-2026-69708 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Web Platform Storage is a Windows component that manages browser-related data storage. A use-after-free vulnerability in this component allows an authorized local user to escalate their privileges to a higher level of system access, potentially enabling unauthorized control over the system.

Technical details

A use-after-free vulnerability exists in Windows Web Platform Storage, where freed memory is accessed after deallocation, leading to potential memory corruption. The vulnerability requires the attacker to be an authorized local user. The attack vector is local, and successful exploitation allows privilege escalation from a standard user context to a higher privilege level. Patches are available from Microsoft.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats