You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2026-42978
About this tag
CVE-2026-42978 is an Important-rated elevation-of-privilege vulnerability in Windows Push Notifications, disclosed by Microsoft on June 9, 2026. The flaw allows a local, low-privilege attacker to exploit a race condition and gain SYSTEM privileges. It affects supported Windows 10, Windows 11, and Windows Server releases. Patches are available through the June 2026 security updates. While not a remote-code-execution vulnerability and considered unlikely to be exploited, the local privilege escalation vector is a common concern for enterprise IT and security teams. Discussions on WindowsForum highlight the practical importance of such bugs in real networks despite their lower severity rating.
Microsoft disclosed CVE-2026-42978 on June 9, 2026, as an Important-rated Windows Push Notifications elevation-of-privilege vulnerability affecting supported Windows 10, Windows 11, and Windows Server releases, with patches available through the June security updates. The flaw is not a...