Junglewise Threat Intelligence

CVE-2026-42991: Microsoft Windows Push Notifications privilege escalation via race condition

CVE-2026-42991 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Microsoft Windows Push Notifications. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Push Notification service, which handles real-time alerts and updates for applications. An attacker who already has limited access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.

Technical details

A race condition (CWE-362) exists in the Windows Push Notifications service due to improper synchronization when accessing shared resources. This flaw can lead to a use-after-free (CWE-416) scenario, which an attacker can leverage to execute code with elevated privileges. The attack requires local access and is characterized by high complexity, as the attacker must successfully time the concurrent execution to trigger the synchronization error. If successful, the attacker can bypass security boundaries and gain SYSTEM-level access.

Affected products

  • Microsoft Windows Push Notifications

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats