CVE-2026-24282 is an out-of-bounds read vulnerability in the Push Message Routing Service, impacting various versions of Microsoft Windows 10 and 11. Rated as medium severity (CVSS 5.5), this flaw allows an authorized, local attacker to achieve high confidentiality impact by disclosing sensitive information. Exploitation requires low privileges and local access, with low attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community attention, and it is not present in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.14393.8957CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:* | ||
< 10.0.14393.8957CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:* | ||
< 10.0.17763.8511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.8511CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19044.7058CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.