Description
Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free bug that occurs within the Windows Shell component. When an attacker with local authorisation exploits the flaw, the operating system incorrectly reuses a freed memory reference, allowing the attacker to execute code with elevated privileges. The primary consequence is that a user who can run local processes can gain administrative rights or otherwise bypass user‑level restrictions, potentially compromising system integrity and confidentiality.

Affected Systems

Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1 and Microsoft Windows Server 2025 (Server Core installation) are impacted. Both ARM64 and x64 architectures for the Windows 11 releases are affected, while the Server 2025 release is impacted regardless of architecture.

Risk and Exploitability

This flaw has a CVSS score of 7, indicating moderate to high severity. The EPSS score is not available, so the current likelihood of exploitation in the wild is unknown; however, the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, requiring an attacker to be authenticated or otherwise authorised to run processes on the target machine. If successfully exploited, an attacker can gain system‑level permissions, bypassing normal access controls and potentially escalating privileges further.

Generated by OpenCVE AI on September 8, 2026 at 22:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Microsoft security update for the impacted Windows 11 or Server 2025 releases as published on Windows Update or the Microsoft Security Update Guide.
  • Disable or remove any third‑party shell extensions or custom shell elements that rely on the vulnerable component until the patch is installed, thereby reducing the attack surface.
  • Deploy Windows Defender Application Control or a similar policy to restrict the execution of unauthorized shell commands, limiting the impact of any remaining exploitation attempts while patches are pending.

Generated by OpenCVE AI on September 8, 2026 at 22:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
Title Windows Shell Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 23h2 Windows 11 23h2 Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:35:53.618Z

Reserved: 2026-08-03T21:21:00.594Z

Link: CVE-2026-69606

cve-icon Vulnrichment

Updated: 2026-09-09T09:56:51.430Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:31.693

Modified: 2026-09-21T17:01:00.777

Link: CVE-2026-69606

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:57:55Z

Weaknesses