Use-after-free in Microsoft Windows and Windows Server - CVE-2026-69392
Published: September 8, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Shell when winning a race condition. A local user can exploit the race condition to escalate privileges.
Successful exploitation can elevate privileges from a low integrity level in a contained sandboxed execution environment to a medium integrity level.
Affected software
Windows Server
How to mitigate CVE-2026-69392
Windows Server - update to 2025 10.0.26100.33438