Executive brief
Windows Win32K, a core kernel-mode graphics component on Windows systems, contains a use of uninitialized memory that allows an authenticated local attacker to read sensitive information from system memory. This could leak configuration details, credentials, or other confidential data that an attacker could leverage for further system compromise.
Technical details
The vulnerability is a use of uninitialized resource in Windows Win32K, allowing information disclosure. The attack requires local access and authenticated user privileges on the target system. An attacker with these preconditions can read uninitialized kernel memory through the Win32K subsystem, potentially disclosing sensitive information such as kernel pointers, credentials, or other protected data. A patch is available from Microsoft.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed