CVE-2026-32069 is a double free vulnerability in Windows Projected File System that enables privilege escalation on affected systems. An authorized local attacker can exploit this memory corruption flaw to gain elevated privileges without user interaction. The vulnerability carries a CVSS score of 7.8 (HIGH) with a local attack vector, low complexity, and low privilege requirements, resulting in high impact to confidentiality, integrity, and availability. Currently, this vulnerability shows minimal exploitation activity with an EPSS score of 0.0005 and no presence on the Known Exploited Vulnerabilities catalog, indicating limited real-world active exploitation at this time. The community attention level remains low, reflected in the FAUCET Risk Score of 39.0 out of 100 and its inactive status on security hotlists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.