ZeroHour

CVE-2026-69280

mass

Use-After-Free Local Privilege Escalation in Windows Push Notifications

CVSS 3.1
7.0 high
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-69280 is a use-after-free memory corruption flaw (CWE-416) in the Windows Push Notifications component of Microsoft Windows. An authorized local attacker — meaning a user or process already running with low privileges on the machine — can trigger the bug, which involves high attack complexity and likely requires winning a timing race to reuse freed memory. Successful exploitation elevates the attacker's privileges locally, with high impact on confidentiality, integrity, and availability of the host. All Windows installations containing the affected Push Notifications component are in scope, with the specific affected version ranges enumerated in Microsoft's advisory (not specified in the available data). There is currently no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns it only a 0.2% probability of exploitation within 30 days.

What to do: Check Microsoft's advisory for the exact affected builds and apply the corresponding security update through Windows Update or your patch-management channel once released. Until patched, reduce risk on sensitive hosts by limiting interactive logon and local code execution to trusted users, since exploitation requires low-privileged local access. Given high attack complexity and no known exploitation, standard patching cadence is defensible, but prioritize multi-user hosts and terminal/RDS servers.

Affected
Microsoft Windows (Push Notifications component)
Estimated exposure
mass≫1,000,000 systems (Push Notifications is a default component of broadly deployed Windows client and server editions) — Windows runs on over a billion active devices and the Push Notifications component ships by default with the OS, so nearly every unpatched Windows installation is plausibly affected, though exploitation requires local code execution.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.