Junglewise Threat Intelligence

CVE-2026-69300: Microsoft Windows Push Notifications privilege escalation

CVE-2026-69300 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows Push Notifications. Vendors: Microsoft.

Executive brief

Windows Push Notifications is a system service used to deliver notifications to users on Windows devices. A use-after-free vulnerability in this service allows an authenticated local attacker to execute code with elevated privileges, potentially gaining administrative control of the system.

Technical details

A use-after-free vulnerability exists in the Windows Push Notifications service. An authenticated local attacker can trigger the vulnerability through a malicious action, causing the service to reference memory that has already been freed. This memory corruption flaw can be leveraged to achieve arbitrary code execution with elevated privileges on the affected system. The vulnerability requires local access and prior authentication to exploit.

Affected products

  • Microsoft Windows Push Notifications

Timeline

  • 2026-09-08: disclosed

References

Related threats