Executive brief
Windows Win32K is a core kernel-mode driver that manages graphics and window operations on every Windows system. A use-after-free vulnerability allows a locally authenticated attacker to crash the system or execute code with elevated privileges, potentially leading to full system compromise or lateral movement within an enterprise.
Technical details
This is a use-after-free vulnerability in the Windows Win32K kernel-mode driver. The vulnerability requires local access and authenticated user privileges to trigger. An attacker can manipulate memory objects to cause the kernel to reference freed memory, leading to code execution with kernel-level privileges. The attack requires user-level access to the system; remote exploitation is not possible. A patch has been released by Microsoft as part of their security updates.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed