ZeroHour

CVE-2026-62697

mass

Use-After-Free Local Privilege Escalation in Windows Push Notifications

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-62697 is a use-after-free memory corruption flaw (CWE-416) in the Windows Push Notifications component of Microsoft Windows. An authorized attacker — one who already has low-privileged local access — can trigger the flaw without user interaction, causing the Push Notifications service to use freed memory and execute code at elevated privilege. Successful exploitation yields high impact on confidentiality, integrity, and availability on the local system, effectively letting a local user or malware escalate from an unprivileged account to a privileged one. Because the component is part of the Windows operating system, the flaw is broadly relevant to Windows deployments, with practical risk concentrated on systems where untrusted users or code run locally. Exploitation status is currently quiet: no public proof-of-concept is known, the CVE is not in CISA KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days.

What to do: Install Microsoft's security update for CVE-2026-62697 through Windows Update as part of your regular patch cycle, prioritizing multi-user and untrusted-user systems such as RDS hosts, VDI, and kiosks. Because there is no known in-the-wild exploitation or public PoC, standard cadence patching is a reasonable priority level. Consult Microsoft's advisory to confirm the exact affected product and version scope, since the source data does not specify version ranges.

Affected
Microsoft Windows Push Notifications (Windows OS component)
Estimated exposure
mass≈1 billion+ Windows devices (component enabled by default across the Windows installed base) — Microsoft has publicly reported a Windows installed base of more than 1.4 billion active devices, and the Push Notifications component ships by default on Windows clients and servers, so the exposed population is effectively the entire…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.