Description
Use after free in Audio Video Control Transport Protocol allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

A use‑after‑free flaw in the Audio Video Control Transport Protocol enables an authenticated local attacker to elevate privileges. The vulnerability allows the attacker to execute code after the protocol’s memory object has been freed, resulting in a privilege escalation on the affected machine.

Affected Systems

Microsoft Windows 11 24H2, 25H2 (arm64) and 26H1 (x64) as well as Windows Server 2025, including Server Core installations, are impacted. The flaw exists in the AVCTP implementation shipped with these operating systems.

Risk and Exploitability

The CVSS score of 7 indicates a moderate severity rating, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so the current exploitation likelihood is uncertain. The attack vector is local: an authorized user or process must trigger the use‑after‑free in AVCTP to gain higher privileges. A successful exploit would allow the attacker to elevate privileges on the local system, potentially compromising confidentiality, integrity, and availability of local resources.

Generated by OpenCVE AI on September 10, 2026 at 01:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update that addresses CVE-2026-69401 to all affected Windows 11 and Windows Server 2025 systems.
  • Disable or restrict the Audio Video Control Transport Protocol (AVCTP) service on endpoints where Bluetooth audio functionality is not required to reduce the attack surface.
  • Configure Windows Update to automatically download and install critical security updates, ensuring future vulnerability fixes are applied promptly.

Generated by OpenCVE AI on September 10, 2026 at 01:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)

Thu, 10 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in Audio Video Control Transport Protocol allows an authorized attacker to elevate privileges locally.
Title Audio Video Control Transport Protocol Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:31:12.590Z

Reserved: 2026-08-03T20:57:58.963Z

Link: CVE-2026-69401

cve-icon Vulnrichment

Updated: 2026-09-09T10:04:03.912Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:19:02.413

Modified: 2026-09-09T10:18:25.873

Link: CVE-2026-69401

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:12:52Z

Weaknesses