Windows Win32k Elevation of Privilege Vulnerability
An out-of-bounds read vulnerability exists in Windows Win32k (the graphics and window management kernel subsystem). An attacker with standard user credentials could exploit this flaw to read memory outside of intended bounds, potentially leading to privilege escalation to SYSTEM level. The vulnerability affects multiple Windows 10 versions, Windows 11, Windows Server 2019, 2022, and 2025 across all supported architectures (32-bit, x64, ARM64). Microsoft has released patches in the September 2026 security update with specific build numbers for each Windows version.
- Standard user credentials (not admin)
- Interactive access to an affected Windows system or ability to interact with a logged-in user
- User interaction with attacker-supplied content
Patching may require device reboot — plan for process interruption
/api/v1/advisories/25132b42-3645-43f1-89ef-f9abae78fba6Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.