Win32k Information Disclosure Vulnerability

Low RiskCVSS 3.3CVE-2026-50416Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A vulnerability in Windows Win32K allows an authorized local user to read sensitive information from kernel memory that should be restricted. The issue affects Windows 11 and Windows Server 2025 across multiple builds and architectures.

What this means
What could happen
An attacker with local access to a Windows system could read sensitive information from kernel memory that they should not be able to access. This is a low-severity local issue that does not affect remote operations or cause system compromise.
Who's at risk
Windows administrators managing Windows 11 or Windows Server 2025 systems should care about this issue. Servers exposed to untrusted local users or staff are at higher risk, particularly those in publicly accessible facilities or environments where contractor/vendor accounts exist.
How it could be exploited
An attacker who already has a user account on the Windows system could execute code locally to read portions of kernel memory through the Win32K component, extracting sensitive information that would normally be protected. This requires the attacker to already be on the system—it cannot be exploited remotely.
Prerequisites
  • Local user account on the Windows system
  • Ability to execute code in user context
low severity information disclosurerequires local accesslow exploit probability
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Public Proof-of-Concept (PoC) on GitHub (1 repository)
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.8875
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.8875
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.8875
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.8875
Windows Server 2025All versionsBuild 10.0.26100.33158
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2525
Windows 11 Version 26H1 for ARM64-based SystemsAll versionsBuild 10.0.28000.2525
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2025
HOTFIXApply the July 2026 Windows security update to Windows 11 and Windows Server 2025
API: /api/v1/advisories/73a80afa-8374-4007-a0bc-7a2d9b2b401f

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Win32k Information Disclosure Vulnerability | CVSS 3.3 - OTPulse