Junglewise Threat Intelligence

CVE-2026-57095: Microsoft Windows Win32K information exposure privilege escalation

CVE-2026-57095 · Severity: medium · CVSS 6.2 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Win32K component, which handles graphics and window management. An attacker who already has basic access to a computer could exploit this flaw to view sensitive information that they are not authorized to see. This information could then be used to gain higher-level administrative control over the system.

Technical details

This vulnerability is classified as an Information Exposure (CWE-200) within the Windows Win32K kernel-mode driver. The flaw allows an unauthorized actor to access sensitive data residing in kernel memory. While the primary impact is confidentiality loss, Microsoft notes that this exposure can be leveraged by a local attacker to facilitate an elevation of privilege. The attack requires local access to the target machine but does not require administrative rights or user interaction. Patches are available via the Microsoft Security Update Guide for various versions of Windows 10, Windows 11, and Windows Server 2012.

Affected products

  • Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 Versions 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All editions including Server Core

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats