CVE-2026-32159

7.8

Microsoft · Windows

A race condition vulnerability in Windows Push Notifications allows a local, authenticated attacker to achieve privilege escalation.

Executive summary

A race condition vulnerability in the Windows Push Notifications component allows an authenticated attacker to elevate privileges on the local system.

Vulnerability

This vulnerability involves a race condition (CWE-362) and a use-after-free (CWE-416) within the Windows Push Notifications service, requiring the attacker to possess local, authenticated access to the target system.

Business impact

Successful exploitation of this flaw allows a local user to escalate their privileges to a higher level, potentially gaining full control over the affected system. With a CVSS score of 7.8, this vulnerability represents a high risk as it facilitates horizontal or vertical movement within an environment, which could lead to unauthorized data access or the installation of persistent malicious code.

Remediation

Immediate Action: Administrators must apply the latest Microsoft security updates corresponding to the affected Windows versions listed above.

Proactive Monitoring: Review system logs for unusual process execution patterns or service crashes related to the Windows Push Notifications service.

Compensating Controls: Ensure that user account controls are strictly enforced and that standard users are not granted unnecessary administrative rights, which limits the initial access required to trigger this flaw.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for privilege escalation and full system compromise, this vulnerability should be prioritized for remediation during the standard monthly update cycle. System administrators should verify that all Windows endpoints are patched to the versions specified in the enrichment data to eliminate the risk of local exploitation.

More Microsoft CVEs

Sources