CVE-2026-32162 is a privilege escalation vulnerability in Windows COM that allows unauthorized attackers to elevate privileges by mixing untrusted data with trusted data during local processing. The vulnerability affects Windows operating systems and related COM components, though specific product versions are not detailed in the available information. The vulnerability carries a HIGH severity rating with a CVSS score of 8.4, reflecting significant risk across all impact categories. The attack requires local access but demands no special privileges or user interaction, making it relatively straightforward to exploit, while the compromise results in complete system integrity and confidentiality breaches. There is currently no indication of active exploitation in the wild, as the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on security hot lists. The extremely low EPSS score of 0.0004 suggests minimal real-world exploitation probability to date, indicating this remains a potential rather than actively weaponized threat requiring proactive mitigation efforts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.