Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2965 articles · 110870 vulns · 36/41 feeds (7d)
← Back to list
7.0
CVE-2026-32075EXPLOITEDPATCHED
Microsoft · Windows 10 Version 1607

Windows UPnP Device Host Elevation of Privilege Vulnerability

Description

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

Affected Products

VendorProductVersions
MicrosoftWindows 10 Version 160710.0.14393.0, 10.0.17763.0, 10.0.19044.0, 10.0.19045.0, 10.0.22631.0, 10.0.22631.0, 10.0.26100.0, 10.0.26200.0, 10.0.28000.0, 6.2.9200.0, 6.2.9200.0, 6.3.9600.0, 6.3.9600.0, 10.0.14393.0, 10.0.14393.0, 10.0.17763.0, 10.0.17763.0, 10.0.20348.0, 10.0.25398.0, 10.0.26100.0, 10.0.26100.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftwindows 11 version 25h2mitre_affected90%
microsoftwindows server 2019 (server core installation)mitre_affected90%
microsoftwindows 11 version 26h1mitre_affected90%
microsoftwindows 10 version 22h2mitre_affected90%
microsoftwindows 11 version 23h2mitre_affected90%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32075(vendor-advisory, patch)

Related News (3 articles)

Tier C
Qualys Blog3h ago
Microsoft and Adobe Patch Tuesday, April 2026 Security Update Review
→ No new info (linked only)
Tier C
VulDB6h ago
CVE-2026-32075 | Microsoft Windows up to Server 2025 UPnP Device Host use after free
→ No new info (linked only)
Tier A
Microsoft MSRC10h ago
CVE-2026-32075 Windows UPnP Device Host Elevation of Privilege Vulnerability
→ No new info (linked only)
CVSS 3.17.0 HIGH
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
10.0.14393.906010.0.17763.864410.0.19044.718410.0.19045.718410.0.22631.693610.0.26100.3269010.0.26200.824610.0.28000.18366.2.9200.260266.3.9600.2313210.0.20348.502010.0.25398.2274
CWECWE-416
PublishedApr 14, 2026
Last enriched6h agov2
Trending Score66
Source articles3
Independent3
Info Completeness9/14
Missing: title, epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-32201EXPKEV
Microsoft SharePoint Server Spoofing Vulnerability
Trending: 150
LOWCVE-2026-26171EXP
.NET Denial of Service Vulnerability
Trending: 70
CRITICALCVE-2026-33824EXP
Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
Trending: 68
HIGHCVE-2026-32071EXP
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
Trending: 67
HIGHCVE-2026-32093EXP
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
Trending: 66

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 14, 2026
Discovered by ZDM
Apr 14, 2026
Updated: description, exploitAvailable, activelyExploited
Apr 14, 2026
Actively Exploited
Apr 14, 2026
Exploit Available
Apr 14, 2026
Patch Available
Apr 14, 2026

Version History

v2
Last enriched 6h ago
v2Tier A6h ago

Added a detailed description of the vulnerability and marked it as actively exploited with an exploit available.

descriptionexploitAvailableactivelyExploited
via Microsoft MSRC
v16h ago

Initial creation