ZeroHour

CVE-2026-69300

mass

Use-after-free local privilege escalation in Windows Push Notifications

CVSS 3.1
7.0 high
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-69300 is a use-after-free memory-corruption flaw (CWE-416) in the Windows Push Notifications component of Microsoft Windows. It is triggered by an authorized local user who induces the stale-pointer condition; the high attack complexity rating means exploitation depends on specific timing or memory-layout conditions rather than straightforward input. Successful exploitation allows the attacker to run code with elevated privileges on the local system, with high impact on confidentiality, integrity, and availability. Any Windows installation carrying the push notification component is potentially affected, though the source data does not specify exact affected version ranges, so defenders should verify against Microsoft's advisory. Exploitation is currently quiet: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for Windows as soon as it is released, prioritizing multi-user machines, RDP-exposed hosts, and admin/developer workstations where local privilege escalation is most damaging. Until patched, restrict local interactive logon rights to trusted users and monitor Microsoft's advisory for the confirmed affected version list.

Affected
Microsoft Windows Push Notifications (Windows operating system component)
Estimated exposure
masshundreds of millions of Windows endpoints (component ships with the OS) — Push notifications are a standard Windows component present on typical Windows client and server installs, so exposure is effectively the size of the Windows installed base (on the order of a billion devices) rather than a niche deployment.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.