Junglewise Threat Intelligence

CVE-2026-69808: Microsoft Windows Win32K out-of-bounds read

CVE-2026-69808 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Windows Win32K is a core kernel component that manages graphics and window display operations. An authorized local attacker can exploit an out-of-bounds read vulnerability to disclose sensitive system information, potentially exposing credentials, encryption keys, or other confidential data residing in kernel memory.

Technical details

A heap or stack-based out-of-bounds read vulnerability exists in the Windows Win32K kernel subsystem. The vulnerability requires local authentication and can be triggered through a specially crafted input or API call. An attacker with local access can read memory beyond allocated buffer boundaries to extract sensitive kernel information. The CVSS v3.1 base score is 5.5 (medium severity), reflecting the requirement for local authentication and the information disclosure impact. Microsoft has released security updates to address this vulnerability.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats