Junglewise Threat Intelligence

CVE-2026-32224: Microsoft Windows Server Update Service use after free privilege escalation

CVE-2026-32224 · Severity: high · CVSS 7 · Published 2026-04-14

Technologies: Microsoft Windows 11 Version 26H1, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Server Update Service (WSUS) component of Windows 11. This service is responsible for managing and distributing software updates across corporate networks. If exploited, a user who already has limited access to a computer could gain full administrative control, potentially allowing them to access sensitive data or disrupt system operations.

Technical details

A use-after-free (CWE-416) vulnerability exists within the Windows Server Update Service (WSUS) component. The flaw is triggered when the service incorrectly manages memory objects, allowing an attacker to reuse a memory pointer after it has been freed. To exploit this, an attacker must first have local access to the system with low-level privileges. While the attack complexity is rated as high—likely requiring specific timing or race conditions—a successful exploit allows the attacker to gain SYSTEM-level privileges. Microsoft has released security updates to address this issue in Windows 11 version 26H1.

Affected products

  • Microsoft Windows 11 version 26H1 up to (excluding) 10.0.28000.1836

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory: Microsoft released the security update guide for this vulnerability.

References

Related threats