Win32k Information Disclosure Vulnerability
MonitorCVSS 5.5CVE-2026-56184Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Win32k kernel information disclosure vulnerability allows an authorized local user to read sensitive kernel memory. An attacker with a valid local account can exploit this through specific Win32k function calls to access data that should not be readable from user mode, exposing system secrets or privileged information locally only.
What this means
What could happen
A local user with valid Windows credentials could read sensitive kernel memory through Win32k, potentially exposing system secrets or other privileged data. This is a local-only risk and does not enable remote access or system compromise by itself.
Who's at risk
Organizations running Windows 10, Windows 11, Windows Server 2022, or Windows Server 2025 are affected regardless of architecture (x64, 32-bit, or ARM64). This impacts both server infrastructure and end-user workstations, particularly those in environments where local user accounts are shared or contractor access is permitted.
How it could be exploited
An attacker with a local user account on the affected Windows system could call specific Win32k functions to access kernel memory that should not be readable from user mode, extracting sensitive information without triggering security alerts.
Prerequisites
- Valid local user account on the affected Windows system
- Local network or physical access to log in
- No special privileges required beyond standard user permissions
No authentication required beyond valid local accountLow complexity attackLow exploit probability (0.5% EPSS)Not actively exploitedInformation disclosure only—no code execution
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (15)
15 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1HARDENINGRestrict local system access to trusted users only; disable or remove unneeded local accounts
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXApply Microsoft's July 2026 security update to all affected Windows systems
HOTFIXPrioritize patching Windows Server systems first, then workstations
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/148bc563-efab-4967-a966-acad1cdccbf7Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.