Executive brief
Windows Win32K is a core kernel component that manages graphics and window display operations on all Windows systems. A buffer over-read flaw allows authenticated attackers to read sensitive memory and escalate their privileges to system level, potentially enabling complete system compromise or unauthorized access to protected data.
Technical details
This vulnerability is a buffer over-read condition in the Windows Win32K kernel driver, a critical component handling graphics and windowing system operations. The flaw permits an authenticated local attacker to read out-of-bounds memory, which can be leveraged to gain higher privilege levels (privilege escalation). The attack requires local access and valid credentials. Microsoft has released a patch to address this issue; users should apply the latest security updates.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed