CVE-2026-42978

HIGH

Microsoft Windows 10 Version 1809 - Windows Push Notifications Elevation of Privilege Vulnerability

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-42978. PoCs published by grizzzer.

AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2026-42978, demonstrating a TOCTOU (Time-of-Check Time-of-Use) race condition vulnerability in a mock Windows Push Notifications service. It includes both vulnerable and patched versions of the service, an attacker tool to exploit the race condition, and detection scripts for monitoring exploitation attempts.

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

Exploits (1)

github WORKING POC
by grizzzer · cpoc
https://github.com/grizzzer/CVE-2026-42978-PoC-Research

This repository contains a functional proof-of-concept for CVE-2026-42978, demonstrating a TOCTOU (Time-of-Check Time-of-Use) race condition vulnerability in a mock Windows Push Notifications service. It includes both vulnerable and patched versions of the service, an attacker tool to exploit the race condition, and detection scripts for monitoring exploitation attempts.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: Windows Push Notifications Service (mock implementation for educational purposes)
No auth needed
Prerequisites: Windows environment · Administrator privileges for detection scripts · Compiled vulnerable service and attacker tool
mistral-large-3 · analyzed Jun 24, 2026 Full analysis →

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
Windows Push Notifications Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42978

Scores

CVSS v3 7.8
EPSS 0.0025
EPSS Percentile 16.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-362 CWE-416
Status published
Products (22)
Microsoft/Windows 10 Version 1809 10.0.17763.0 - 10.0.17763.8880
Microsoft/Windows 10 Version 21H2 10.0.19044.0 - 10.0.19044.7417
Microsoft/Windows 10 Version 22H2 10.0.19045.0 - 10.0.19045.7417
Microsoft/Windows 11 version 23H2 10.0.22631.0 - 10.0.22631.7219
Microsoft/Windows 11 Version 24H2 10.0.26100.0 - 10.0.26100.8655
Microsoft/Windows 11 Version 25H2 10.0.26200.0 - 10.0.26200.8655
Microsoft/Windows 11 version 26H1 10.0.28000.0 - 10.0.28000.2269
Microsoft/Windows Server 2019 10.0.17763.0 - 10.0.17763.8880
Microsoft/Windows Server 2019 (Server Core installation) 10.0.17763.0 - 10.0.17763.8880
Microsoft/Windows Server 2022 10.0.20348.0 - 10.0.20348.5256
... and 12 more
Published Jun 09, 2026
Tracked Since Jun 09, 2026