Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-62690

CVE-2026-62690: Windows 10 1809 Privilege Escalation Flaw

CVE-2026-62690 is a privilege escalation vulnerability in Windows 10 1809 affecting Push Notifications. A race condition allows authenticated attackers to gain elevated privileges locally.

Updated:

CVE-2026-62690 Overview

CVE-2026-62690 is a race condition vulnerability in the Windows Push Notifications component. The flaw stems from concurrent execution using a shared resource with improper synchronization [CWE-362]. An authorized local attacker who wins the race can elevate privileges on the affected system. Microsoft has assigned this issue a CVSS 3.1 base score of 7.0, and it affects a broad range of Windows client and server versions including Windows 10, Windows 11, and Windows Server 2019 through 2025. No public exploit code or in-the-wild exploitation has been reported at the time of publication.

Critical Impact

A local attacker with low privileges who successfully exploits the race condition can gain elevated privileges, resulting in full compromise of confidentiality, integrity, and availability on the host.

Affected Products

  • Microsoft Windows 10 (versions 1809, 21H2, 22H2)
  • Microsoft Windows 11 (versions 23H2, 24H2, 25H2, 26H1)
  • Microsoft Windows Server 2019, 2022, and 2025

Discovery Timeline

  • 2026-08-11 - CVE-2026-62690 published to NVD
  • 2026-08-13 - Last updated in NVD database

Technical Details for CVE-2026-62690

Vulnerability Analysis

The vulnerability resides in the Windows Push Notifications service, which handles toast and background notification delivery for applications. Multiple threads or processes access a shared resource without adequate synchronization primitives. An authorized local attacker running low-privileged code can manipulate the timing of these concurrent operations to reach an inconsistent state. When the race is won, the attacker gains elevated privileges on the local host, enabling full read, write, and control over affected resources. Attack complexity is rated High because exploitation depends on precise timing and repeated attempts against a narrow window.

Root Cause

The root cause is improper synchronization of concurrent access to a shared resource inside the Push Notifications component. Without a proper lock, ordering guarantee, or atomic operation, an attacker-controlled thread can interleave operations with the privileged service thread. This condition is classified as [CWE-362] Concurrent Execution using Shared Resource with Improper Synchronization.

Attack Vector

Exploitation requires local access and an existing low-privileged account on the target. The attacker executes code that repeatedly triggers Push Notifications operations while a second thread races to substitute or modify the shared resource. Successful interleaving grants the attacker access to a privileged operation performed by the service, producing an elevation of privilege. No user interaction is required beyond the attacker's own local execution. Microsoft's advisory for CVE-2026-62690 is available in the Microsoft Security Update Guide.

Detection Methods for CVE-2026-62690

Indicators of Compromise

  • Unexpected child processes spawned by the Windows Push Notifications service (WpnUserService, WpnService) running with elevated tokens.
  • Repeated, high-frequency API calls from a single low-privileged process targeting Push Notifications interfaces, characteristic of race-window brute forcing.
  • New privileged local accounts, scheduled tasks, or services created shortly after anomalous Push Notifications activity.

Detection Strategies

  • Baseline normal behavior for WpnUserService and alert on token elevation or handle duplication involving that service.
  • Hunt for local process trees where a low-integrity process performs rapid, looped notification API calls followed by privileged actions.
  • Correlate Windows Security event log entries for privilege assignment (Event ID 4672) with parent processes tied to notification subsystems.

Monitoring Recommendations

  • Ingest Sysmon process creation, handle access, and thread injection events into a central SIEM for behavioral analysis.
  • Track patch state across all Windows 10, Windows 11, and Windows Server 2019/2022/2025 endpoints to identify unpatched hosts.
  • Monitor for post-exploitation behaviors such as LSASS access, credential dumping, and lateral movement following any privilege escalation attempt.

How to Mitigate CVE-2026-62690

Immediate Actions Required

  • Apply the Microsoft security update referenced in the Microsoft Security Update Guide for CVE-2026-62690 to all affected Windows client and server versions.
  • Prioritize patch deployment on multi-user systems, jump hosts, and terminal servers where untrusted local users can execute code.
  • Audit local accounts and restrict interactive logon rights to reduce the population of principals able to attempt local exploitation.

Patch Information

Microsoft has released fixes through the Security Update Guide for all affected products, including Windows 10 1809/21H2/22H2, Windows 11 23H2/24H2/25H2/26H1, and Windows Server 2019/2022/2025. Administrators should deploy the corresponding cumulative update for each supported build and verify installation via Windows Update history or Get-HotFix.

Workarounds

  • No official vendor workaround is published; patching is the supported remediation path.
  • Where patching must be delayed, restrict local logon and remote interactive sessions to trusted administrators to reduce the attack surface.
  • Enforce application allowlisting to block unauthorized binaries from executing the repeated API calls needed to win the race window.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.