Junglewise Threat Intelligence

CVE-2026-33841: Microsoft Windows Kernel heap buffer overflow privilege escalation

CVE-2026-33841 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Microsoft Windows 11 Version 25H2, Microsoft Windows 11 Version 24H2, Microsoft Windows 10 Version 22H2, Microsoft Windows, Microsoft Windows 11 Version 26H1, Microsoft Windows Server 2022, Microsoft Windows 11 Version 23H2, Microsoft Windows 10 Version 21H2. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Kernel, the core component of the Microsoft Windows operating system. This flaw allows a user who already has basic access to a computer to gain full administrative control. Such an exploit could be used by an attacker to bypass security restrictions, access sensitive data, or install malicious software across the system.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists within the Windows Kernel. The flaw is triggered when the kernel improperly handles memory allocation on the heap, allowing a local attacker with low-privileged user credentials to execute code with SYSTEM privileges. The attack vector is local, requiring the attacker to already have an account or a foothold on the target machine. Successful exploitation results in a complete compromise of system integrity, confidentiality, and availability. Microsoft has released security updates to address this issue across various versions of Windows 10, Windows 11, and Windows Server 2022.

Affected products

  • Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7291
  • Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7417
  • Microsoft Windows 11 Version 23H2 10.0.22631.0 to 10.0.22631.7219
  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8457
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8457
  • Microsoft Windows 11 Version 26H1 10.0.28000.0 to 10.0.28000.2113
  • Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.5139

Timeline

  • 2026-05-12: disclosed
  • 2026-06-17: other: Advisory modified by Microsoft

References

Related threats