CVE-2026-32083 is a race condition vulnerability in the Windows SSDP Service that permits authorized local users to escalate their privileges through improper synchronization of concurrent resource execution. The flaw affects Windows systems running the SSDP service component. The vulnerability carries a HIGH severity rating with a CVSS score of 7.0, reflecting local attack vector requirements and high complexity conditions, but with significant potential impact including confidentiality, integrity, and availability compromise. Exploitation requires local access and user-level privileges, limiting the attack surface to authenticated threat actors already present on the system. The vulnerability demonstrates minimal exploitation activity, with no current inclusion on the Known Exploited Vulnerabilities catalog and extremely low EPSS probability of 0.0004, indicating negligible active exploitation in the wild. Community attention remains low, and no public exploit code has achieved widespread distribution. Organizations should prioritize this issue based on their internal exposure to untrusted local users rather than external threat landscape pressure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.14393.9060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:* | ||
< 10.0.14393.9060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.