CVE-2026-42978
HIGHMicrosoft Windows 10 Version 1809 - Windows Push Notifications Elevation of Privilege Vulnerability
Title source: ruleExploitation Summary
EIP tracks 1 public exploit for CVE-2026-42978. PoCs published by grizzzer.
AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2026-42978, demonstrating a TOCTOU (Time-of-Check Time-of-Use) race condition vulnerability in a mock Windows Push Notifications service. It includes both vulnerable and patched versions of the service, an attacker tool to exploit the race condition, and detection scripts for monitoring exploitation attempts.
Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
Exploits (1)
This repository contains a functional proof-of-concept for CVE-2026-42978, demonstrating a TOCTOU (Time-of-Check Time-of-Use) race condition vulnerability in a mock Windows Push Notifications service. It includes both vulnerable and patched versions of the service, an attacker tool to exploit the race condition, and detection scripts for monitoring exploitation attempts.
References (1)
Scores
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H