Windows Win32k Elevation of Privilege Vulnerability
A time-of-check time-of-use (TOCTOU) race condition in Windows Win32K kernel allows a standard user with local access to escalate privileges to system level. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64-based, and ARM64-based architectures. Exploitation requires the attacker to already have a user account and local code execution capability, but no administrator credentials are needed. Microsoft has released patches for all affected versions.
- Local user account (standard user, not administrator)
- Ability to execute code on the target Windows system
- Physical or RDP/remote access to the system
Patching may require device reboot — plan for process interruption
/api/v1/advisories/33e71173-47fe-4fe4-a973-7ac373b05494Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.