Win32k Information Disclosure Vulnerability

MonitorCVSS 5.6CVE-2026-69832Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

Win32K (Windows kernel graphics subsystem) contains an information disclosure vulnerability that allows an authorized local user to read sensitive system memory that should be restricted to their privilege level. An attacker with a local user account could exploit this to extract kernel memory contents or data from higher-privilege processes, potentially revealing information that can be used to defeat security mechanisms or plan further attacks.

What this means
What could happen
An authorized local user could read sensitive Windows system information they are not supposed to access, such as kernel memory or privileged process data. This could be used to defeat security protections or gather information for follow-up attacks.
Who's at risk
Organizations running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 on engineering workstations, OT networks, or servers that host sensitive systems. Particular concern for shared workstations, remote access systems (RDP), or any machine where local user accounts can be created by non-administrators.
How it could be exploited
An attacker with a local user account on the Windows system could call Win32K API functions to trigger the information disclosure and read sensitive memory regions. No network access is required, but the attacker must already have a login session on the affected machine.
Prerequisites
  • Local user account credentials required to log in to the Windows system
  • User must have interactive logon session capability
  • No special privileges required beyond standard user access
Requires local account access to exploitLow complexity to trigger once authenticatedInformation disclosure could enable privilege escalation or bypass of protectionsAffects all recent Windows versions
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXApply the September 2026 Windows security update to all affected systems (install latest build for your Windows version and architecture)
HARDENINGPrioritize patching of systems that allow local logons from untrusted users or shared workstations
Long-term hardening
0/1
HARDENINGRestrict local logon access to domain accounts and disable Guest accounts if not required
API: /api/v1/advisories/3510a3e5-c681-4fef-83b8-f89e9a9c7e58

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Win32k Information Disclosure Vulnerability | CVSS 5.6 - OTPulse