Description
Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Use after free bug in the Windows Push Notifications component allows an authorized local user to increase privileges on a Windows system. The flaw can be triggered by manipulating the memory management of the push notification service, leading to a use after free situation that exploits attacker control to gain elevated rights. This local privilege escalation can enable an attacker to compromise the security of the machine and potentially install unauthorized software. The flaw maps to CWE‑416: Use After Free.

Affected Systems

Microsoft Windows 10 versions 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, Windows Server 2022, and Windows Server 2025 (including Server Core installations) are all affected by this vulnerability.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, and the vulnerability can be exploited by an authorized local attacker. Although the EPSS score is not available, the lack of a KEV listing suggests it has not yet been publicly exploited at scale. Attackers would need local access to trigger the use‑after‑free, but once achieved, they can elevate privileges and potentially take full control of the system. Effective mitigation requires timely patching.

Generated by OpenCVE AI on September 8, 2026 at 18:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft Windows security update that addresses CVE-2026-62697 on all affected Windows 10, Windows 11, and Windows Server 2022/2025 systems.
  • Configure Windows Update or WSUS to deliver and apply the latest security patches automatically so future fixes are applied in a timely manner.
  • If the Windows Push Notifications service is not needed on a given system, consider disabling or restricting the service to reduce the attack surface.

Generated by OpenCVE AI on September 8, 2026 at 18:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
Title Windows Push Notifications Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 21h2 Windows 10 22h2 Windows 11 23h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T19:17:38.783Z

Reserved: 2026-07-14T20:56:21.890Z

Link: CVE-2026-62697

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:17:52.523

Modified: 2026-09-08T18:38:46.007

Link: CVE-2026-62697

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T19:00:13Z

Weaknesses