Junglewise Threat Intelligence

CVE-2026-42979: Microsoft Windows Push Notifications race condition privilege escalation

CVE-2026-42979 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Microsoft Windows Push Notifications. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Push Notification service, which handles the delivery of alerts and updates to applications. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to access sensitive data, install malicious software, or disrupt business operations.

Technical details

A race condition (CWE-362) exists in the Windows Push Notifications service due to improper synchronization when accessing shared resources. This flaw can lead to a use-after-free (CWE-416) scenario. An attacker with low-privileged local access can exploit this vulnerability by timing specific requests to the service. Successful exploitation allows the attacker to escape their current security context and gain elevated system privileges. The attack complexity is considered high because it requires precise timing to trigger the race condition.

Affected products

  • Microsoft Windows Push Notifications

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats