Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-42978-PoC-Research — CVE-2026-42978 Windows Push Notifications (WpnService) Use-After-Free & Race Condition PoC research, diagnostic scanner, and security audit module for AI Security Tool. | Kitploit
Tools/GitHubGitHub/syntaxmethod/cve-2026-42978-poc-research
Defensive ToolsPrivilege EscalationVulnerability ScannersVulnerability AnalysisExploitationThreat IntelligencePapers & ResearchLearning & Education

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHub
syntaxmethod/cve-2026-42978-poc-research

CVE-2026-42978-PoC-Research

CVE-2026-42978 Windows Push Notifications (WpnService) Use-After-Free & Race Condition PoC research, diagnostic scanner, and security audit module for AI Security Tool.

View RepositoryWebsite
942321 days agoNot yet reviewed
Share

CVE-2026-42978
Windows Push Notifications Module for AI Security Tool

Next-Gen AI Security Ecosystem, Multi-Protocol Terminal & Autonomous Agent Suite


Latest Release Build Status Donations Telegram Channel License

Website · Product docs · Host application · Community chat

Website navigation: Home · Updates · Downloads · Modules

Module banner


Official host application

Product: AI Security Tool
Site: zerodayevil.github.io
Docs: https://zerodayevil.github.io/ai-security-tool

This module is a reviewed write-up and a safe check profile for AI Security Tool.
Use only modules listed on the project site or in the official catalog. Load this module inside the approved application, against endpoints you own or are written-authorized to assess.

This repository does not ship a weaponized exploit against WpnService. The lab under lab/ is a standalone mock of the class of bug (TOCTOU / double-fetch). It does not talk to the real push-notification service.


Quick start & installation

Install the host application first. Then enable this module from Modules → Windows / Local EoP → CVE-2026-42978.

Ready-to-use builds

OS / platformVersionArchitecture / formatUpdatedStatusDownload
Windowsv6.3.20x64 installer (.exe)2026-09-08LatestDownload .exe
Windowsv6.3.20x64 portable (.tar.gz)2026-09-08LatestDownload .tar.gz
macOSv5.3.29Apple Silicon (.dmg)2026-09-05StableDownload .dmg
Linuxv5.3.27Universal x64 (.tar.gz)2026-09-01StableDownload .tar.gz
Androidv5.3.27ARM64 APK (.apk)2026-09-01StableDownload .apk

Official sources only:

  • https://zerodayevil.github.io/
  • https://zerodayevil.github.io/ai-security-tool
  • https://github.com/ZeroDayEvil/ai-security-tool

Conceptual overview

CVE-2026-42978 is a local elevation of privilege in Windows Push Notifications. Microsoft describes concurrent access to a shared resource without proper synchronization (CWE-362). Research on patched vs. unpatched wpncore.dll shows a use-after-free race in PresentationEndpointFacade during platform shutdown.

WpnService runs in session 0 as NT AUTHORITY\SYSTEM (svchost.exe -k netsvcs -p). Toast, tile and badge delivery go through it. A won race against that process is a SYSTEM problem on the local machine — not a remote pre-auth DC bug.

Status: patched on 10 June 2026 (Patch Tuesday). This page is defensive research.

It is not CVE-2026-41089 (Netlogon RCE). Different component, different privilege model, different patch date.


Specifications

FieldValue
CVECVE-2026-42978
BDUBDU:2026-08249
Vendor advisoryMSRC — Windows Push Notifications EoP
SeverityHigh · CVSS 3.1 7.8
WeaknessCWE-362 race condition · use-after-free on the shutdown path
ComponentWindows Push Notifications · WpnService · wpncore.dll
Attack vectorLocal
Privileges requiredLow (authorized local user)
User interactionNone
Patch Tuesday10 June 2026
Module typeResearch write-up + in-app safe check + detection pack

Scope

Client and server SKUs that ship Push Notifications. Confirm the exact KB on MSRC before you close a ticket.

FamilyNotes
Windows 101809, 21H2, 22H2 (x86 / x64 / ARM64 as applicable)
Windows 1123H2, 24H2, 25H2, 26H1
Windows Server2016 / 2019 / 2022 / 2025 (full and Server Core where the component exists)

Orientation builds from public servicing notes (always re-check MSRC):

BranchIndicative patched build
Windows 11 23H222631.7219
Windows 11 24H226100.8655
Windows 11 25H226200.8655
Windows 11 26H128000.2269
wpncore.dll example (24H2)vulnerable 26100.8521 → patched 26100.8655

Root cause (research)

The facade wraps notification API calls and delegates to PresentationEndpointImpl. During platform shutdown the NotificationPlatform object is destroyed. Several facade methods historically took a platform pointer without a shutdown flag or a shared lock. If teardown wins the race, the next call uses a dangling pointer.

Facade, platform, shutdown guard

Same lock-and-guard pattern was applied across 49 PresentationEndpointFacade::* methods. Implementation methods underneath were left as-is — the hole sat at the facade.

Unpatched shape (wpncore.dll 26100.8521)

// PresentationEndpointFacade::ToastUnblockAll — unpatched
long ToastUnblockAll(PresentationEndpointFacade *this) {
    NotificationPlatformHandle::Get(this + 0x50);
    if (platform == NULL)
        Throw_Hr(...);
    return PresentationEndpointImpl::UnblockToastsForEachApp(...);
}

Patched shape (wpncore.dll 26100.8655)

Download Tool