Description
Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The kernel streaming WOW thunk service driver contains a use‑after‑free bug that enables an attacker who already has local access to the system to gain elevated privileges. By freeing a kernel memory buffer and then accessing it again, the attacker can corrupt kernel state or execute arbitrary code with elevated rights, compromising the confidentiality or integrity of the entire machine. This vulnerability is classified as CWE‑416 and carries a medium‑severity CVSS score of 7.

Affected Systems

This flaw affects a wide range of Microsoft Windows operating systems. The affected products include Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 23H2, 24H2, 25H2, 26H1, and the 23H2 variant; and all Windows Server editions from 2012 through 2025, whether in server core or full installation mode. The specific CPE strings indicate both 32‑bit and 64‑bit architectures, including ARM64 for some Windows 11 builds.

Risk and Exploitability

The vulnerability is local and requires an authorized attacker who can execute code on the affected machine to trigger the use‑after‑free condition. The CVSS score of 7 indicates a moderate risk, and the EPSS score is currently unavailable, providing no additional insight into exploitation likelihood. The flaw is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited in the wild. Organizations should treat it a medium‑severity concern, given the potential for privilege escalation if the flaw remains unpatched.

Generated by OpenCVE AI on September 8, 2026 at 20:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update that patches the Kernel Streaming WOW thunk service driver for CVE‑2026‑69275.
  • If the patch is not yet available for your version, block or disable the use of the affected driver through Group Policy or AppLocker, ensuring only privileged users can load it, and consider deploying Windows Defender Application Control to prevent unauthorized execution.
  • Perform regular privileged access reviews and monitor for local privilege escalation attempts; enforce least‑privilege principles.

Generated by OpenCVE AI on September 8, 2026 at 20:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
Title Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 23h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T23:38:01.618Z

Reserved: 2026-08-03T20:44:03.597Z

Link: CVE-2026-69275

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:40.847

Modified: 2026-09-08T18:39:13.460

Link: CVE-2026-69275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T21:00:12Z

Weaknesses