• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-69451: authenticated privilege escalation in Microsoft Windows 10 Version 1607

An authenticated attacker with network access can exploit a use-after-free vulnerability in Windows Management Instrumentation to elevate privileges on Windows installations. CVE-2026-69451 affects multiple Windows 10, Windows 11, and Windows Server builds (for example Windows 10 Version 1607 up to before 10.0.14393.9512, Windows 10/11 branches listed in vendor advisories, and Windows Server 2012 builds before 6.2.9200.26349). Exploitation requires an authorized account and network access and may require user interaction according to vendor data and CVSS metadata.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
7.1HIGH
EPSS
0.0057
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists, so prioritize patching exposed systems; this is especially critical for internet-accessible hosts because an authenticated network attacker can gain elevated privileges.

What is CVE-2026-69451?

An authenticated attacker with network access can exploit a use-after-free vulnerability in Windows Management Instrumentation to elevate privileges on Windows installations. CVE-2026-69451 affects multiple Windows 10, Windows 11, and Windows Server builds (for example Windows 10 Version 1607 up to before 10.0.14393.9512, Windows 10/11 branches listed in vendor advisories, and Windows Server 2012 builds before 6.2.9200.26349). Exploitation requires an authorized account and network access and may require user interaction according to vendor data and CVSS metadata. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349

Is CVE-2026-69451 being exploited?

Public exploit code is available.

How to fix CVE-2026-69451

  1. Apply Microsoft updates that include the fixed builds such as 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, or 6.2.9200.26349 where applicable.
  2. Restrict network exposure of systems running the affected Windows branches and require network segmentation for management interfaces.
  3. Monitor authentication logs and Windows event logs for unusual account activity and privilege escalation attempts.
  4. Follow Microsoft guidance for any additional mitigations and verify updates are installed across endpoints and servers.

Frequently asked questions

Is CVE-2026-69451 being actively exploited?

Public exploit code is available for CVE-2026-69451; there are no CISA Known Exploited Vulnerabilities catalog entries for it as of the provided date.

Which Windows 10 Version 1607 versions are affected by CVE-2026-69451?

Windows 10 Version 1607 builds from 10.0.14393.0 up to but not including 10.0.14393.9512 are listed as affected for CVE-2026-69451.

Is there a patch for CVE-2026-69451?

Yes. Microsoft published updates that fix the issue; affected branches have fixed builds such as 10.0.14393.9512 and later as listed in the vendor's affected builds.

Does CVE-2026-69451 require authentication?

Yes. The vulnerability requires an authorized account and network access to exploit, per the vendor description and CVSS metadata.

References