CVE-2026-32083
vulnerability analysis and mitigation

Overview

CVE-2026-32083 is a race condition vulnerability in the Windows SSDP (Simple Service Discovery Protocol) Service that allows an authenticated local attacker with low privileges to elevate privileges on the affected system. It was disclosed and patched on April 14, 2026, as part of Microsoft's monthly Patch Tuesday security updates. The vulnerability affects a broad range of Windows versions, including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2012/2012 R2, 2016, 2019, 2022, 2022 23H2, and Windows Server 2025. It carries a CVSS v3.1 base score of 7.0 (High) (Microsoft MSRC, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization — Race Condition). The Windows SSDP Service contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which that resource can be modified by another concurrently executing code sequence. An attacker with low-level local access can exploit this timing window to manipulate the shared resource and trigger a privilege escalation. The attack vector is local, requires low privileges, no user interaction, and has high attack complexity, meaning exploitation requires precise timing and is not trivially repeatable. Attack patterns associated with this vulnerability include CAPEC-26 (Leveraging Race Conditions) and CAPEC-29 (Leveraging TOCTOU Race Conditions) (Microsoft MSRC, GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker with low privileges to escalate to SYSTEM-level access on the affected Windows host, resulting in high confidentiality, integrity, and availability impact. With SYSTEM privileges, an attacker could access sensitive data, install malware or backdoors, modify system configurations, and potentially move laterally within the network by leveraging the compromised host as a pivot point. The attack is limited to the local system scope (no scope change), but the consequences of full privilege escalation are severe (Microsoft MSRC, GitHub Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Microsoft MSRC). The EPSS score is approximately 0.036–0.047%, placing it in the lower percentiles for near-term exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The high attack complexity (requiring precise race condition timing) further reduces the likelihood of widespread exploitation in the short term.

Mitigation and workarounds

Microsoft released security updates on April 14, 2026 addressing this vulnerability across all affected platforms. Organizations should apply the relevant cumulative updates to reach the following patched build versions: Windows 10 1607/Server 2016 (10.0.14393.9060), Windows 10 1809/Server 2019 (10.0.17763.8644), Windows 10 21H2 (10.0.19044.7184), Windows 10 22H2 (10.0.19045.7184), Windows Server 2022 (10.0.20348.5020), Windows Server 2022 23H2 (10.0.25398.2274), Windows 11 23H2 (10.0.22631.6936), Windows 11 24H2/Server 2025 (10.0.26100.8246 / 10.0.26100.32690), Windows 11 25H2 (10.0.26200.8246), Windows 11 26H1 (10.0.28000.1836), and Windows Server 2012/2012 R2 (6.2.9200.26026 / 6.3.9600.23132). As interim mitigations, enforce the principle of least privilege, restrict local access to sensitive systems, and monitor for anomalous SYSTEM-level process execution originating from low-privileged accounts (Microsoft MSRC).

Community reactions

The vulnerability was covered as part of broader Microsoft April 2026 Patch Tuesday roundups by security vendors including Sophos and Lansweeper, as well as threat intelligence outlets such as NSFocus and CyberSecurity News (Sophos Blog, Lansweeper Blog, NSFocus). No notable individual researcher commentary or significant social media discussion specific to this CVE has been identified, consistent with its moderate severity and lack of public exploit code.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management