Executive brief
A security vulnerability exists in the Windows kernel-mode driver responsible for graphics and window management. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to bypass security restrictions, access sensitive data, or install malicious software.
Technical details
This vulnerability is a race condition (CWE-362) within the Windows Win32K - GRFX component, specifically involving improper synchronization of shared resources. While initial reports suggested a Use-After-Free (CWE-416) in the ICOMP component, the updated advisory confirms the root cause as a synchronization issue in the GRFX subsystem. An attacker with local access and standard user privileges can exploit this flaw to achieve local privilege escalation (LPE). Successful exploitation allows the attacker to execute code with SYSTEM privileges. Microsoft has released security updates to address this issue across affected versions of Windows 11 and Windows Server 2025.
Affected products
- Microsoft Windows 11 24H2 up to (excluding) 10.0.26100.8390
- Microsoft Windows 11 25H2 up to (excluding) 10.0.26200.8390
- Microsoft Windows 11 26H1 up to (excluding) 10.0.28000.2113
- Microsoft Windows Server 2025 up to (excluding) 10.0.26100.32772
Timeline
- 2026-05-12: disclosed: Initial disclosure by Microsoft
- 2026-05-12: advisory: NVD published the CVE record
- 2026-06-01: other: Vulnerability description updated from Use-After-Free to Race Condition