CVE-2026-26172
7.8Microsoft · Windows
A race condition in Windows Push Notifications allows a locally authenticated attacker to elevate privileges on affected Windows systems.
Executive summary
A race condition vulnerability in the Windows Push Notifications service allows a locally authenticated attacker to gain elevated privileges on the host system.
Vulnerability
This vulnerability is a race condition (CWE-362) within the Windows Push Notifications component, which can also manifest as a use after free (CWE-416). An attacker must already possess local, low-level authentication to trigger this condition and escalate their system privileges.
Business impact
Successful exploitation grants an attacker elevated privileges, potentially allowing full control over the compromised workstation or server. With a CVSS score of 7.8, this vulnerability represents a high-severity risk to organizational security, as it facilitates lateral movement and unauthorized access to sensitive data or administrative functions.
Remediation
Immediate Action: Apply the relevant security updates provided by Microsoft in the official update guide to address the identified race condition.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected service restarts related to the Push Notifications component.
Compensating Controls: Ensure that local user permissions follow the principle of least privilege to restrict the ability of non-administrative users to execute malicious code or interact with vulnerable system services.
Exploitation status
Public Exploit Available: No (exploit_available: unknown).
Analyst recommendation
Given the potential for complete privilege escalation, organizations should prioritize the deployment of the identified security patches across all affected Windows endpoints. System administrators should verify that all listed builds are updated to the specified non-vulnerable versions to mitigate the risk of local exploitation.
More Microsoft CVEs
Sources
- Windows Push Notifications Elevation of Privilege Vulnerability Vendor advisory