Microsoft disclosed several Windows Simple Search and Discovery Protocol (SSDP) Service elevation-of-privilege vulnerabilities, including CVE-2026-32082, CVE-2025-48815, CVE-2025-47975, and CVE-2025-59196, indicating a recurring security issue affecting the Windows SSDP component. The advisories identify the flaws as local privilege-escalation bugs that could allow an attacker with existing low-privilege access to gain administrator-level rights on a vulnerable system.
For CVE-2026-32082, Microsoft said the issue stems from a race condition (CWE-362) and rated it Important with a CVSS 3.1 score of 7.0. The company described exploitation as requiring local access and low privileges, with high impact to confidentiality, integrity, and availability if successful. Microsoft said exploitation was considered less likely, was not publicly disclosed or known to be exploited at publication, and that a security update was available.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft disclosed CVE-2026-32083 in the Windows Simple Search and Discovery Protocol (SSDP) Service via its Security Update Guide. The publication indicates an official fix was released for this separate elevation-of-privilege vulnerability.
Microsoft disclosed CVE-2026-32082 as an Important Windows SSDP Service elevation-of-privilege flaw caused by a race condition (CWE-362). The company said a low-privileged local attacker could gain administrator privileges, exploitation was less likely, there was no evidence of public disclosure or in-the-wild exploitation, and an official fix was available.
Microsoft disclosed CVE-2026-32068 in the Windows Simple Search and Discovery Protocol (SSDP) Service through its Security Update Guide. The publication indicates an official fix was released for this separate elevation-of-privilege vulnerability.
Microsoft published a Security Update Guide entry for CVE-2025-59196, an elevation-of-privilege vulnerability in the Windows Simple Search and Discovery Protocol (SSDP) Service.
Microsoft published a Security Update Guide entry for CVE-2025-48815, another elevation-of-privilege vulnerability affecting the Windows Simple Search and Discovery Protocol (SSDP) Service.
Microsoft published a Security Update Guide entry for CVE-2025-47975, an elevation-of-privilege vulnerability affecting the Windows Simple Search and Discovery Protocol (SSDP) Service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
6 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.