Win32k Information Disclosure Vulnerability

MonitorCVSS 5.5CVE-2026-56184Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Win32k kernel information disclosure vulnerability allows an authorized local user to read sensitive kernel memory. An attacker with a valid local account can exploit this through specific Win32k function calls to access data that should not be readable from user mode, exposing system secrets or privileged information locally only.

What this means
What could happen
A local user with valid Windows credentials could read sensitive kernel memory through Win32k, potentially exposing system secrets or other privileged data. This is a local-only risk and does not enable remote access or system compromise by itself.
Who's at risk
Organizations running Windows 10, Windows 11, Windows Server 2022, or Windows Server 2025 are affected regardless of architecture (x64, 32-bit, or ARM64). This impacts both server infrastructure and end-user workstations, particularly those in environments where local user accounts are shared or contractor access is permitted.
How it could be exploited
An attacker with a local user account on the affected Windows system could call specific Win32k functions to access kernel memory that should not be readable from user mode, extracting sensitive information without triggering security alerts.
Prerequisites
  • Valid local user account on the affected Windows system
  • Local network or physical access to log in
  • No special privileges required beyond standard user permissions
No authentication required beyond valid local accountLow complexity attackLow exploit probability (0.5% EPSS)Not actively exploitedInformation disclosure only—no code execution
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (15)
15 with fix
ProductAffected VersionsFix Status
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows 10 Version 21H2 for 32-bit SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 21H2 for ARM64-based SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 21H2 for x64-based SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 22H2 for x64-based SystemsAll versionsBuild 10.0.19045.7548
Windows 10 Version 22H2 for ARM64-based SystemsAll versionsBuild 10.0.19045.7548
Windows 10 Version 22H2 for 32-bit SystemsAll versionsBuild 10.0.19045.7548
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Remediation & Mitigation
0/3
Do now
0/1
HARDENINGRestrict local system access to trusted users only; disable or remove unneeded local accounts
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXApply Microsoft's July 2026 security update to all affected Windows systems
HOTFIXPrioritize patching Windows Server systems first, then workstations
API: /api/v1/advisories/148bc563-efab-4967-a966-acad1cdccbf7

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.