Junglewise Threat Intelligence

CVE-2026-35420: Microsoft Windows Kernel heap buffer overflow privilege escalation

CVE-2026-35420 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the core of the Microsoft Windows operating system. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to access sensitive data, install malicious software, or disrupt business operations.

Technical details

A heap-based buffer overflow (CWE-122) exists within the Windows Kernel. The vulnerability is triggered when the kernel improperly handles memory allocation on the heap, allowing an attacker to overwrite adjacent memory. To exploit this, an attacker must first have local access to the system with low-level user privileges. Successful exploitation allows the attacker to execute code with SYSTEM privileges, effectively gaining full control over the affected host. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats