CVE-2026-32212: Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
Other sources
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.1836Patch KB5083768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.26026Patch KB5082127 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23132Patch KB5082126 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8246Patch KB5083769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9060Patch KB5082198 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32690Patch KB5082063 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2274Patch KB5082060 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8246Patch KB5083769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6936Patch KB5082052 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.7184Patch KB5082200 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8644Patch KB5082123 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.7184Patch KB5082200 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5020Patch KB5082142
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32212?
CVE-2026-32212 is classified as an Information Disclosure vulnerability.
How do I fix CVE-2026-32212?
To mitigate CVE-2026-32212, install the latest security patches provided by Microsoft for the affected systems.
Which products are affected by CVE-2026-32212?
CVE-2026-32212 affects various versions of Microsoft Windows, including Windows Server 2012, Windows Server 2016, Windows 10, and Windows 11.
Can CVE-2026-32212 be exploited remotely?
No, CVE-2026-32212 requires local access for an attacker to exploit the vulnerability.
What is the impact of CVE-2026-32212?
The impact of CVE-2026-32212 is that it allows an authorized attacker to disclose sensitive information locally.