Executive brief
A security vulnerability exists in the Windows Win32K component, which manages graphics and windowing for the operating system. An attacker who already has basic access to a computer could exploit this flaw to view sensitive information that should normally be protected. This could lead to the exposure of system secrets or data belonging to other users on the same machine.
Technical details
An information disclosure vulnerability exists in the Windows Win32K kernel-mode driver (CWE-200). The flaw allows a locally authenticated attacker with low privileges to bypass security restrictions and read sensitive information from the system's memory. The attack vector is local, meaning the attacker must already have the ability to execute code on the target system. Successful exploitation results in a high impact on confidentiality but does not directly impact system integrity or availability. Microsoft has released security updates to address this issue across affected versions of Windows 10, 11, and Windows Server.
Affected products
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2525
- Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.5386
- Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD
- 2026-07-14: patched: Security updates released by Microsoft