Improper Access Control Vulnerability in Microsoft Universal Plug and Play
CVE-2026-32214
5.5MEDIUM
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 14 April 2026
What is CVE-2026-32214?
An improper access control vulnerability in Universal Plug and Play (upnp.dll) can be exploited by an authorized attacker to disclose sensitive information locally. This issue emphasizes the importance of ensuring robust access controls within such network protocols to safeguard against unauthorized information disclosure.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9060
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8644
Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7184