CVE-2026-32158

7.8

Microsoft · Windows

A race condition vulnerability in Windows Push Notifications allows an authorized local attacker to achieve privilege escalation through improper resource synchronization.

Executive summary

A critical race condition in Microsoft Windows Push Notifications could allow an authenticated local attacker to escalate privileges and gain full control over the affected system.

Vulnerability

The vulnerability is a race condition (CWE-362) and use after free (CWE-416) within the Windows Push Notifications component. An attacker with low-level local privileges can exploit this flaw to execute arbitrary code with elevated permissions.

Business impact

The ability for a low-privileged user to escalate to higher privileges poses a significant risk to organizational security, as it facilitates lateral movement and unauthorized access to sensitive data. With a CVSS score of 7.8, this high-severity vulnerability represents a substantial threat to system integrity and confidentiality. Successful exploitation could lead to total system compromise, potentially allowing an attacker to bypass security controls and disable endpoint protection.

Remediation

Immediate Action: Deploy the security updates provided by Microsoft for the affected Windows versions as listed in the Microsoft Update Guide.

Proactive Monitoring: Audit system logs for unexpected privilege escalation events, abnormal process execution, or unauthorized attempts to access protected system resources.

Compensating Controls: Ensure endpoint detection and response systems are configured to detect suspicious child process creation originating from system services or notification processes.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for complete privilege escalation, organizations should prioritize the deployment of the provided security patches across all affected Windows endpoints. Administrators must ensure that all systems within the identified build ranges are updated to the specified secure versions to eliminate the risk of local exploitation.

More Microsoft CVEs

Sources