Junglewise Threat Intelligence

CVE-2026-65678: Microsoft Windows Win32K use-after-free privilege escalation

CVE-2026-65678 · Severity: high · CVSS 7 · Published 2026-08-11

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Win32K is a core kernel component that manages graphics and windowing on all Windows systems. A use-after-free vulnerability allows a user with local access to execute arbitrary code with elevated system privileges, potentially enabling full system compromise and persistent malware installation.

Technical details

This is a use-after-free memory safety vulnerability in the Win32K kernel subsystem. An authorized local attacker can trigger a memory access after it has been freed, allowing arbitrary code execution in kernel context. The vulnerability requires local access and authentication but no user interaction is needed. Successful exploitation results in privilege escalation to SYSTEM level. Microsoft has issued a security patch to address this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-08-11: disclosed

References

Related threats