CVE-2026-32080: Windows WalletService Elevation of Privilege Vulnerability
Use after free in Windows WalletService allows an authorized attacker to elevate privileges locally.
Other sources
Windows WalletService Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32690Patch KB5082063 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5020Patch KB5082142 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9060Patch KB5082198 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8644Patch KB5082123 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2274Patch KB5082060
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32080?
CVE-2026-32080 has a high severity rating due to its potential to allow local privilege escalation.
How do I fix CVE-2026-32080?
To fix CVE-2026-32080, apply the relevant security patches provided by Microsoft for your affected Windows Server version.
What version of Windows Server is affected by CVE-2026-32080?
CVE-2026-32080 affects multiple Windows Server versions including 2016, 2019, 2022, and 2025.
Can CVE-2026-32080 be exploited remotely?
No, CVE-2026-32080 can only be exploited locally by an authorized attacker.
What is the impact of CVE-2026-32080 on my system?
The impact of CVE-2026-32080 may allow an attacker to elevate privileges on the system, potentially leading to unauthorized access to sensitive information.