Win32k Information Disclosure Vulnerability
MonitorCVSS 5.5CVE-2026-62786Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Win32k out-of-bounds read vulnerability in Windows 10, Windows 11, and Windows Server allows an authorized local attacker to disclose information from kernel memory. An attacker with local system access could exploit this to read sensitive data. The vulnerability is unlikely to be exploited in the wild. Microsoft has released fixes for all affected Windows versions.
What this means
What could happen
An attacker with local access to a Windows system could read sensitive information from system memory, potentially exposing passwords, encryption keys, or other protected data stored in kernel memory.
Who's at risk
Windows IT administrators should prioritize patching Windows 10 (all versions), Windows 11 (all versions), Windows Server 2016, 2019, 2022, and 2025 systems. This affects workstations, servers, and any industrial control system computers running these operating systems, though the vulnerability requires local access and is unlikely to be exploited in typical OT networks where systems have restricted logon access.
How it could be exploited
An attacker must have local logon access to the system. They would execute code locally to trigger an out-of-bounds read in the Windows graphical kernel (Win32k), allowing them to read memory regions they should not be able to access.
Prerequisites
- Local logon access to the Windows system
- Ability to execute code on the local system
Affects multiple Windows operating systemsRequires local authenticationLow exploit probability (0.3% EPSS)
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the August 2026 Windows security update to your Windows 10, Windows 11, or Windows Server systems
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/a299590d-e21e-437e-ac45-d16db70f90a8Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.