CVE-2026-69890 – Windows Virtual Trusted Platform Module Elevation of Privilege Vulnerability

CVSS 7.5 IMPORTANT Critical - Same Day Deployment

“A successful race-condition attack could turn existing privileged access into powerful VTL1 control, putting system confidentiality, integrity, and availability at risk.”

CVE-2026-69890 is a use-after-free vulnerability in the Windows Virtual Trusted Platform Module that allows an authorized local attacker to elevate privileges. Successful exploitation requires high existing privileges and winning a race condition, but could give the attacker Virtual Trust Level 1 (VTL1) privileges. No user interaction is required.

Key Details

Attack Vector
Local
Attack Complexity
High
Privileges Required
High
User Interaction
None
CWE Classification
CWE-416
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.