Executive brief
Windows Win32K is a core kernel subsystem that manages graphics, windows, and user interface rendering on Windows systems. A use-after-free vulnerability allows an authenticated local user to execute arbitrary code with elevated privileges, potentially compromising the entire system.
Technical details
A use-after-free vulnerability exists in the Windows Win32K kernel subsystem. An authenticated attacker with local access can trigger the vulnerability to gain privilege escalation from a standard user context to a higher privilege level. The attack requires local code execution capability and does not require network access. Successful exploitation allows an attacker to execute arbitrary code in kernel context, leading to complete system compromise. A patch has been released by Microsoft.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed