Home
HIGH: 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.17763.0 (custom) before 10.0.17763.8880
affected
10.0.19044.0 (custom) before 10.0.19044.7417
affected
10.0.19045.0 (custom) before 10.0.19045.7417
affected
10.0.22631.0 (custom) before 10.0.22631.7219
affected
10.0.22631.0 (custom) before 10.0.22631.7219
affected
10.0.26100.0 (custom) before 10.0.26100.8655
affected
10.0.26200.0 (custom) before 10.0.26200.8655
affected
10.0.28000.0 (custom) before 10.0.28000.2269
affected
10.0.17763.0 (custom) before 10.0.17763.8880
affected
10.0.17763.0 (custom) before 10.0.17763.8880
affected
10.0.20348.0 (custom) before 10.0.20348.5256
affected
10.0.26100.0 (custom) before 10.0.26100.32995
affected
10.0.26100.0 (custom) before 10.0.26100.32995
affected
Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
Problem types
CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42977 (Windows Push Notifications Elevation of Privilege Vulnerability)