Junglewise Threat Intelligence

CVE-2026-69816: Microsoft Windows Accounts Control use-after-free privilege escalation

CVE-2026-69816 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

Windows Accounts Control is a Windows system component responsible for managing user accounts and authentication. A use-after-free vulnerability allows an authenticated local user to escalate their privileges to system-level access, potentially compromising the entire computer.

Technical details

The vulnerability is a use-after-free memory error in Windows Accounts Control that can be triggered by an authenticated attacker with local access. The flaw allows an attacker to reference memory that has been deallocated, leading to arbitrary code execution with elevated privileges. This requires prior authentication or local user access to exploit. Microsoft has released security patches to address this issue.

Affected products

  • Microsoft Windows Accounts Control

Timeline

  • 2026-09-08: disclosed

References