CVE-2026-42991 is a local elevation of privilege vulnerability in Windows Push Notifications. The flaw is caused by improper synchronization during concurrent execution on a shared resource, resulting in a race condition. Available vendor information also indicates the presence of a related use-after-free condition in the affected component. An authorized local attacker can exploit this weakness to elevate privileges on the local system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a defensive research and educational PoC for CVE-2026-42978, a local Windows privilege-escalation race/use-after-free in the Windows Push Notifications service (WpnService). It is not a weaponized exploit for the real service. The core exploit-like capability is contained in the lab/ directory: vulnerable_service.c implements a mock local service exposing a named pipe (\\.\pipe\WpnLabPipe) and shared memory object (Local\WpnLabSharedMem), while race_attacker.c connects to that pipe, manipulates the shared memory, and attempts to win a double-fetch race by changing message_length after validation but before use. The vulnerable handler intentionally demonstrates the bug class; the patched handler shows the mitigation by capturing the length once and reusing the local copy. Repository structure is split into three purposes: (1) lab/ contains the educational local race demonstration and build script; (2) detection/ contains defensive monitoring artifacts, including a PowerShell ETW/event-log monitor and a Sysmon configuration for suspicious WPN-related child processes, pipe access, file creation, registry tampering, process access, and thread injection; (3) reports/ contains reverse-engineering patch-diff notes for wpncore.dll and wpnapps.dll, documenting function and PE-level changes associated with Microsoft’s fix. Main capabilities observed: the attacker PoC can open a shared memory mapping, repeatedly flip a length field, send a PROCESS trigger over a named pipe, and induce race-detection/overflow-simulation behavior in the mock service. The detection scripts can enumerate WpnService state, inspect crash history, query WPN event logs, audit notification directories for reparse points, and define Sysmon rules for WPN-related telemetry. There are no hardcoded C2 endpoints, no remote network exploitation routines, and no post-exploitation payload such as a shell or persistence mechanism. Overall, this is a local proof-of-concept and detection/research repository centered on understanding and monitoring the vulnerability class rather than exploiting the real patched Windows component.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.