You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve 2026 24282
About this tag
CVE-2026-24282 is a medium-severity information disclosure vulnerability in the Windows Push Message Routing Service (dmwappushsvc). The flaw is an out-of-bounds read that can be exploited by an authorized local user to leak process memory. Microsoft has released security updates to address the defect. While the vulnerability is easy to mischaracterize, it can become dangerous when chained with other local exploits. Security teams should prioritize patching this issue to prevent potential data exposure. The tag covers discussion of the vulnerability details, affected component, severity, and mitigation steps.
Microsoft’s security catalog has recorded CVE-2026-24282 as an out‑of‑bounds read in the Push Message Routing Service that can be abused by an authorized local user to disclose information from process memory, and Microsoft has released updates to address the defect; security teams should treat...