Executive brief
Windows Win32K is a core system component that handles graphical rendering and display operations. An authenticated local attacker can exploit an out-of-bounds memory read to access sensitive information stored in kernel memory, potentially exposing system secrets or user data.
Technical details
An out-of-bounds read vulnerability exists in Windows Win32K, a kernel-mode driver responsible for graphics subsystem operations. The vulnerability allows an authenticated local attacker to read memory beyond intended boundaries, disclosing sensitive information from kernel memory. The attack requires local access and valid user credentials; remote exploitation is not possible. A successful exploit could lead to information disclosure of privileged data, potentially enabling follow-on attacks. Patches are expected from Microsoft's security update channels.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed