CVE-2026-32093 is a race condition vulnerability in the Windows Function Discovery Service (fdwsd.dll) that permits an authorized local user to escalate their privileges on affected systems. The flaw stems from improper synchronization during concurrent execution when accessing shared resources within the service. The vulnerability carries a CVSS score of 7.0 (HIGH), indicating substantial risk, with a local attack vector requiring high complexity and low-level user privileges. Successful exploitation could allow an attacker to achieve high impact across confidentiality, integrity, and availability. The EPSS score of 0.00055 suggests current real-world exploitation likelihood is minimal relative to the broader CVE landscape. There is no evidence of active exploitation in the wild, and the vulnerability is not currently listed on the KEV catalog or industry hot lists. This nascent threat should be monitored for exploit development, though the high complexity requirement and low EPSS score indicate limited near-term risk for most organizations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.14393.9060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:* | ||
< 10.0.14393.9060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.