Junglewise Threat Intelligence

CVE-2026-34330: Microsoft Windows Win32K race condition in GRFX component

CVE-2026-34330 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Microsoft Windows, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows graphics component that could allow a user with basic access to take full control of a computer. By exploiting a synchronization error in how the system handles shared resources, an attacker can bypass security restrictions to gain administrative privileges. This could lead to unauthorized software installation, data theft, or complete system compromise.

Technical details

This vulnerability is a race condition (CWE-362) within the Windows Win32K - GRFX component, specifically related to improper synchronization during concurrent execution using shared resources. While initial reports also mentioned integer overflow (CWE-190) and use-after-free (CWE-416) weaknesses, the primary root cause is identified as a synchronization issue. An attacker with local access and low privileges can exploit this flaw to execute code with elevated system permissions. The vulnerability affects a wide range of Windows client and server versions, and Microsoft has released security updates to address the issue.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 23H2, 24H2, 26H1
  • Microsoft Windows Server 2012, 2012 R2, 2016, 2019

Timeline

  • 2026-05-12: disclosed: Initial disclosure by Microsoft
  • 2026-05-12: advisory: NVD entry published
  • 2026-06-01: other: Vulnerability description updated from integer overflow to race condition

References

Related threats