Executive brief
Windows Win32K, a core graphics and windowing component in Windows, contains a vulnerability that allows authorized users to access sensitive system information they should not have permission to view. An attacker with local access could exploit this to bypass security boundaries and learn internal system details that could aid in further attacks.
Technical details
This vulnerability is an information disclosure flaw in Windows Win32K that exposes sensitive system information to an unauthorized security context. The vulnerability requires the attacker to be an authorized local user; it cannot be exploited remotely. Successful exploitation allows an attacker to disclose sensitive system information that could facilitate further compromise. The attack vector is local, and a patch is expected to be available via Microsoft security updates.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed