Junglewise Threat Intelligence

CVE-2026-32077: Microsoft Windows UPnP Device Host untrusted pointer dereference

CVE-2026-32077 · Severity: high · CVSS 7.8 · Published 2026-04-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows component responsible for managing Plug and Play devices (UPnP). An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to bypass security restrictions, access sensitive data, or install malicious software across the affected workstation or server.

Technical details

This vulnerability (CWE-822) exists within the Windows Universal Plug and Play (UPnP) Device Host service. It is caused by an untrusted pointer dereference, which occurs when the software processes a pointer provided by an untrusted source without proper validation. A local attacker with low-level privileges can exploit this by running a specially crafted application, leading to an elevation of privileges to SYSTEM. The attack requires local access but no user interaction. Microsoft has released security updates to address this issue across various versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 23H2, 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 R2

Timeline

  • 2026-04-14: disclosed: Initial disclosure by Microsoft
  • 2026-04-14: advisory: NVD published the CVE record
  • 2026-05-26: other: NVD record updated with enrichment data and community scripts

References

Related threats