Junglewise Threat Intelligence

CVE-2026-34333: Microsoft Windows Win32K use after free in GRFX

CVE-2026-34333 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Win32K graphics component, which manages how the operating system displays windows and graphics. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to install programs, view or delete sensitive data, or create new accounts with full user rights.

Technical details

This vulnerability is a use-after-free (UAF) condition within the Windows Win32K GRFX subsystem. The flaw is triggered when the system fails to properly manage memory objects, potentially exacerbated by an underlying integer overflow (CWE-190). An attacker with local access and low-level privileges can exploit this by running a specially crafted application to execute code in kernel mode. Successful exploitation results in a full local privilege escalation (LPE), granting the attacker SYSTEM-level permissions. The vulnerability was disclosed by Microsoft and is tracked as CVE-2026-34333.

Affected products

  • Microsoft Windows Not specified

Timeline

  • 2026-05-12: disclosed: Initial disclosure by Microsoft and NVD publication.
  • 2026-05-12: advisory: Microsoft Security Response Center (MSRC) published the advisory.

References

Related threats