CVE-2026-69280
massUse-After-Free Local Privilege Escalation in Windows Push Notifications
CVE-2026-69280 is a use-after-free memory corruption flaw (CWE-416) in the Windows Push Notifications component of Microsoft Windows. An authorized local attacker — meaning a user or process already running with low privileges on the machine — can trigger the bug, which involves high attack complexity and likely requires winning a timing race to reuse freed memory. Successful exploitation elevates the attacker's privileges locally, with high impact on confidentiality, integrity, and availability of the host. All Windows installations containing the affected Push Notifications component are in scope, with the specific affected version ranges enumerated in Microsoft's advisory (not specified in the available data). There is currently no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns it only a 0.2% probability of exploitation within 30 days.
What to do: Check Microsoft's advisory for the exact affected builds and apply the corresponding security update through Windows Update or your patch-management channel once released. Until patched, reduce risk on sensitive hosts by limiting interactive logon and local code execution to trusted users, since exploitation requires low-privileged local access. Given high attack complexity and no known exploitation, standard patching cadence is defensible, but prioritize multi-user hosts and terminal/RDS servers.
| Microsoft Windows (Push Notifications component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.