Apr 2026: Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-32069 Published on April 14, 2026
Windows Projected File System Elevation of Privilege Vulnerability
Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
Weakness Type
What is a Double-free Vulnerability?
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations. When a program calls free() twice with the same argument, the program's memory management data structures become corrupted. This corruption can cause the program to crash or, in some circumstances, cause two later calls to malloc() to return the same pointer. If malloc() returns the same value twice and the program later gives the attacker control over the data that is written into this doubly-allocated memory, the program becomes vulnerable to a buffer overflow attack.
CVE-2026-32069 has been classified to as a Double-free vulnerability or weakness.
Products Associated with CVE-2026-32069
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Windows 10 Version 1809:- Version 10.0.17763.0 and below 10.0.17763.8644 is affected.
- Version 10.0.19044.0 and below 10.0.19044.7184 is affected.
- Version 10.0.19045.0 and below 10.0.19045.7184 is affected.
- Version 10.0.22631.0 and below 10.0.22631.6936 is affected.
- Version 10.0.22631.0 and below 10.0.22631.6936 is affected.
- Version 10.0.26100.0 and below 10.0.26100.32690 is affected.
- Version 10.0.26200.0 and below 10.0.26200.8246 is affected.
- Version 10.0.28000.0 and below 10.0.28000.1836 is affected.
- Version 10.0.17763.0 and below 10.0.17763.8644 is affected.
- Version 10.0.17763.0 and below 10.0.17763.8644 is affected.
- Version 10.0.20348.0 and below 10.0.20348.5020 is affected.
- Version 10.0.25398.0 and below 10.0.25398.2274 is affected.
- Version 10.0.26100.0 and below 10.0.26100.32690 is affected.
- Version 10.0.26100.0 and below 10.0.26100.32690 is affected.