Description
Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.
Published: 2026-08-11
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An untrusted pointer dereference exists in the Win32K graphics kernel component that allows a local attacker with sufficient privileges to read memory that it should not. This flaw is categorized as CWE-822 and can lead to the disclosure of sensitive data resident in the Windows process address space.

Affected Systems

The flaw affects Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1 and the associated arm64 or x64 builds, as well as Windows Server 2025 and its Server Core installation. These operating systems are listed in official advisories from Microsoft.

Risk and Exploitability

The CVSS score of 5.5 indicates a medium severity impact. The EPSS score of less than 1% suggests that exploitation is considered unlikely at this time, and the vulnerability is not currently flagged in CISA’s KEV catalog. Attackers would need local system or higher level privileges to trigger the vulnerable Win32K functionality, making the attack vector local and authorized. Once the pointer dereference is achieved, the attacker may read protected memory, potentially leaking confidential information.

Generated by OpenCVE AI on August 12, 2026 at 16:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and install the latest Windows security updates from the MSRC update guide linked in the advisory, which contain the fix for the Win32K pointer dereference.
  • Enforce least‑privilege on local accounts; remove or restrict any unnecessary administrator or SYSTEM level access to reduce the opportunity for an authorized attacker to exercise the flaw.
  • Continuously monitor security event logs for unusual Win32K or memory‑related activity and investigate promptly to detect potential exploitation attempts.

Generated by OpenCVE AI on August 12, 2026 at 16:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2025 (server Core Installation)

Thu, 13 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
CPEs cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.
Title Win32k Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-822
CPEs cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 23h2 Windows 11 23h2 Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:05:14.126Z

Reserved: 2026-07-14T21:08:07.965Z

Link: CVE-2026-62798

cve-icon Vulnrichment

Updated: 2026-08-11T20:38:26.770Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:34.040

Modified: 2026-08-13T17:11:51.083

Link: CVE-2026-62798

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:15:03Z

Weaknesses
  • CWE-822

    Untrusted Pointer Dereference