Microsoft · Universal Plug/Play Device Host · CVE-2026-32077
**Name of the Vulnerable Software and Affected Versions**
Windows Universal Plug and Play (UPnP) Device Host (affected versions not specified)
**Description**
An untrusted pointer dereference in the Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.