CVE-2026-69300
massUse-after-free local privilege escalation in Windows Push Notifications
CVE-2026-69300 is a use-after-free memory-corruption flaw (CWE-416) in the Windows Push Notifications component of Microsoft Windows. It is triggered by an authorized local user who induces the stale-pointer condition; the high attack complexity rating means exploitation depends on specific timing or memory-layout conditions rather than straightforward input. Successful exploitation allows the attacker to run code with elevated privileges on the local system, with high impact on confidentiality, integrity, and availability. Any Windows installation carrying the push notification component is potentially affected, though the source data does not specify exact affected version ranges, so defenders should verify against Microsoft's advisory. Exploitation is currently quiet: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for Windows as soon as it is released, prioritizing multi-user machines, RDP-exposed hosts, and admin/developer workstations where local privilege escalation is most damaging. Until patched, restrict local interactive logon rights to trusted users and monitor Microsoft's advisory for the confirmed affected version list.
| Microsoft Windows Push Notifications (Windows operating system component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.