BRIEFING NOTE CVE-2026-32091 is a race condition vulnerability in Microsoft Brokering File System that stems from improper synchronization of concurrent resource access, potentially allowing local attackers to escalate privileges on affected systems. The vulnerability requires low-level user privileges and moderate attack complexity to exploit, but carries high impact across confidentiality, integrity, and availability. This is a local attack vector with a CVSS score of 7.0 (HIGH), indicating significant risk to system security. The attack requires an authenticated user already present on the system, but no user interaction is needed once initiated, making it a credible privilege escalation threat in multi-tenant environments or systems with restricted user accounts. There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed on the Known Exploited Vulnerabilities catalog and has not gained traction on community threat lists. The extremely low EPSS score of 0.000410000 suggests minimal real-world exploitation activity, though organizations should still prioritize patching based on their environment's threat model and the presence of untrusted local users.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.14393.9060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:* | ||
< 10.0.14393.9060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.