Junglewise Threat Intelligence

CVE-2026-42978: Microsoft Windows Push Notifications race condition privilege escalation

CVE-2026-42978 · Severity: high · CVSS 7.8 · Published 2026-06-09

Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Push Notifications service, which handles the delivery of updates and alerts to applications. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to install malicious software, view or delete sensitive data, or create new user accounts with high-level permissions.

Technical details

A race condition (CWE-362) exists in the Windows Push Notifications component due to improper synchronization when accessing shared resources. The vulnerability may also involve a use-after-free (CWE-416) condition triggered during concurrent execution. To exploit this, an attacker must have local access to the system with low privileges and successfully win a timing window to manipulate the service's memory or execution flow. Successful exploitation allows the attacker to escape their current security context and gain SYSTEM-level privileges. Microsoft has released security updates to address this issue via the MSRC Update Guide.

Affected products

  • Microsoft Windows Push Notifications Service (WNS)

Timeline

  • 2026-06-09: advisory: Initial advisory published by Microsoft and NVD.

References