CVE-2026-32212 is a link following vulnerability in the Universal Plug and Play (upnp.dll) library that permits unauthorized disclosure of local information through improper symlink or junction resolution. The flaw affects systems utilizing the vulnerable upnp.dll component and requires local access with standard user privileges to exploit. The vulnerability carries a CVSS score of 5.5 (Medium severity) with a local attack vector and low complexity, meaning a local attacker with limited privileges can trigger the flaw without user interaction. The primary impact is confidentiality loss, allowing information disclosure, while integrity and availability remain unaffected. The EPSS score of 0.000510 indicates this threat is currently ranked lower than 99.84 percent of published vulnerabilities in terms of exploitation probability. There is currently no evidence of active exploitation or public exploit code availability, as reflected by the vulnerability's absence from the Known Exploited Vulnerabilities (KEV) catalog and its inactive status on security hot lists. Community engagement remains limited, suggesting this remains a low-profile vulnerability with minimal real-world threat activity at present.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.14393.9060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:* | ||
< 10.0.14393.9060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.