CVE-2026-32078 is a use-after-free vulnerability in Windows Projected File System that enables an authorized local attacker to achieve privilege escalation on affected systems. This memory safety issue poses a significant risk to Windows environments where multiple users have local access. The vulnerability carries a CVSS score of 7.8 (HIGH) with a local attack vector, low complexity, and low privilege requirements. Successful exploitation results in high impact across confidentiality, integrity, and availability, potentially allowing an attacker to gain elevated system privileges and compromise system security. Current exploitation status indicates this vulnerability is not being actively exploited in the wild, with no public exploit code available and no inclusion on the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score of 0.00049 places it below the median for all CVEs, suggesting lower real-world exploitation probability at this time. However, the FAUCET risk score of 39.0 indicates moderate organizational concern warranting timely patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.