Executive brief
Windows Win32K is a core kernel component that manages graphics and windowing on all Windows systems. A use-after-free vulnerability allows a user with local access to execute arbitrary code with elevated system privileges, potentially enabling full system compromise and persistent malware installation.
Technical details
This is a use-after-free memory safety vulnerability in the Win32K kernel subsystem. An authorized local attacker can trigger a memory access after it has been freed, allowing arbitrary code execution in kernel context. The vulnerability requires local access and authentication but no user interaction is needed. Successful exploitation results in privilege escalation to SYSTEM level. Microsoft has issued a security patch to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-08-11: disclosed