CVE-2026-32068 is a race condition vulnerability in the Windows SSDP Service that enables local privilege escalation by an authorized attacker through improper synchronization of shared resources. The vulnerability affects the SSDP Service component across Windows systems and requires an attacker with local access credentials to trigger. The vulnerability carries a CVSS score of 7.0 (HIGH) with a local attack vector and high complexity, meaning exploitation requires specific timing conditions and local system access with user-level privileges. Successful exploitation results in complete compromise of confidentiality, integrity, and availability on the affected system. The EPSS score of 0.0004 indicates current real-world exploitation probability is minimal. There is currently no evidence of active exploitation in the wild, and the vulnerability does not appear on the KEV or Hot List registries. Community attention remains limited, suggesting either recent disclosure or limited public awareness. Organizations should monitor for exploitation activity while prioritizing patches according to their standard vulnerability management processes.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.14393.9060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:* | ||
< 10.0.14393.9060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.