Junglewise Threat Intelligence

CVE-2026-69890: Microsoft Windows Virtual Trusted Platform Module use-after-free privilege escalation

CVE-2026-69890 · Severity: high · CVSS 7.5 · Published 2026-09-08

Executive brief

Windows Virtual Trusted Platform Module (vTPM) is a security component that manages cryptographic keys and protects sensitive system operations. A use-after-free vulnerability in this component allows an authorized local user to escalate their privileges to a higher privilege level, potentially gaining full system control.

Technical details

A use-after-free vulnerability exists in Windows Virtual Trusted Platform Module, where freed memory is accessed after deallocation, leading to memory corruption. The vulnerability requires that an attacker already has local authentication/authorization on the target system. The attack vector is local, meaning the attacker must execute code with user-level privileges on the affected machine. Successful exploitation allows privilege escalation from an authorized user account to a higher privilege level. Patches are available from Microsoft Security Response Center.

Affected products

  • Microsoft Windows Virtual Trusted Platform Module

Timeline

  • 2026-09-08: disclosed

References