Junglewise Threat Intelligence

CVE-2026-70290: Microsoft Windows Win32 Kernel information disclosure

CVE-2026-70290 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

A vulnerability in the Windows Win32 Kernel Subsystem allows authorized users to read sensitive system memory that should not be accessible, potentially exposing confidential information. An attacker with local access to a system could exploit this flaw to view data from other processes or the kernel itself, compromising the confidentiality of information stored in memory.

Technical details

This vulnerability involves use of an uninitialized resource in the Windows Win32 Kernel Subsystem. The flaw allows an authorized local attacker to disclose information through uninitialized memory that retains data from previous operations. The attack vector is local and requires the attacker to have existing user-level access to the system. By exploiting this condition, an attacker can read sensitive kernel or process data that should have been cleared, leading to information disclosure.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats