Junglewise Threat Intelligence

CVE-2026-24285: Microsoft Windows Win32K use after free privilege escalation

CVE-2026-24285 · Severity: high · CVSS 7 · Published 2026-03-10

Technologies: Microsoft Windows 10, Microsoft Windows Server, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows kernel-mode driver responsible for managing graphics and windowing. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to bypass security restrictions, access sensitive data, or install malicious software across the entire operating system.

Technical details

A use-after-free (UAF) vulnerability exists within the Windows Win32K (win32k.sys) kernel-mode driver, identified as CWE-416. The flaw is triggered when the system incorrectly manages memory objects during graphics or windowing operations, allowing an attacker to reuse memory that has already been freed. To exploit this, an attacker must have local access to the system with low-level user privileges. Successful exploitation enables the attacker to execute code in kernel mode, leading to a full local privilege escalation (LPE) to SYSTEM. Microsoft has released security updates to address this issue across supported versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 23H2, 24H2, 25H2
  • Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 23H2

Timeline

  • 2026-03-10: disclosed: Initial disclosure by Microsoft
  • 2026-03-10: advisory: MSRC advisory published

References

Related threats