Executive brief
A security vulnerability has been identified in the Windows Win32K component, which handles graphics and window management. An attacker who already has basic access to a computer could exploit this flaw to gain higher-level administrative privileges. This could allow them to bypass security restrictions, access sensitive data, or install malicious software that would otherwise be blocked.
Technical details
An improper access control vulnerability (CWE-284) exists in the Windows Win32K kernel-mode driver. The flaw allows a local attacker with low-privileged user access to elevate their permissions to a higher level, such as SYSTEM. Exploitation requires the attacker to execute a specially crafted application on the target system. While the attack vector is local, the complexity is rated as high, suggesting specific timing or system conditions may be required for a successful exploit. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All versions
Timeline
- 2026-07-14: disclosed: Initial publication of the CVE record.
- 2026-07-14: advisory: Microsoft released the Security Update Guide for this vulnerability.