Executive brief
Windows Win32K is a core Windows kernel component that manages display drivers and graphics operations. An out-of-bounds memory read in Win32K can allow an authenticated attacker to read sensitive kernel memory and escalate privileges to gain full system control, potentially enabling malware installation or data theft.
Technical details
This vulnerability is an out-of-bounds read in the Windows Win32K kernel subsystem. The root cause involves improper bounds checking when processing certain requests that an authenticated attacker can trigger over a network. Although the vulnerability requires an authorized account and network connectivity, a successful exploit allows the attacker to read arbitrary kernel memory, which can be leveraged to bypass security protections and escalate privileges. No known public exploits have been reported at this time.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed