CVE-2026-32074 is a double free vulnerability in the Windows Projected File System that allows an authorized local attacker to escalate privileges on affected systems. This memory corruption flaw can be exploited without user interaction by a user with local access rights. The vulnerability carries a CVSS v3.1 score of 7.8 (HIGH) with high impact across confidentiality, integrity, and availability, though it requires local access and existing user privileges to exploit. Exploitation status remains low, with no evidence of active exploitation in the wild, no publicly available exploit code, and minimal community attention, as indicated by the CVE not appearing on Microsoft's Known Exploited Vulnerabilities list and remaining inactive on threat intelligence platforms. The EPSS score of 0.000490 suggests this vulnerability currently poses a relatively low probability of exploitation compared to the broader CVE landscape, though the privilege escalation capability warrants timely patching for systems with untrusted local users.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.