CVE-2026-32085 is a medium-severity information disclosure vulnerability in Windows Remote Procedure Call (RPC) that allows an authorized local attacker to expose sensitive information to unauthorized parties. The vulnerability requires local access and valid credentials to exploit, making it primarily a risk within trusted network environments where user accounts may be compromised. The attack has a low complexity profile with a local attack vector, requiring legitimate user privileges but no user interaction. The impact is limited to confidentiality breach with no effect on system integrity or availability, as reflected in the CVSS 5.5 Medium rating. The FAUCET Risk Score of 33.0/100 indicates moderate concern relative to the broader threat landscape. There is currently no evidence of active exploitation or public exploit availability, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog. The low EPSS score of 0.00044 and inactive hot list status suggest limited real-world exploitation activity and community attention at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.14393.9060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:* | ||
< 10.0.14393.9060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.