ZDI-26-540: (Pwn2Own) Microsoft Windows win32kfull Use-After-Free Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-65776.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-540?
The severity of ZDI-26-540 is rated at 6.5 on the CVSS scale.
How do I fix ZDI-26-540?
To fix ZDI-26-540, ensure that you apply the latest Microsoft Windows updates that address this vulnerability.
Who can exploit ZDI-26-540?
ZDI-26-540 can be exploited by local attackers who have the ability to execute low-privileged code on the target system.
What type of vulnerability is ZDI-26-540?
ZDI-26-540 is a use-after-free information disclosure vulnerability in the Microsoft Windows win32kfull module.
What are the potential consequences of ZDI-26-540?
The potential consequences of ZDI-26-540 include unauthorized disclosure of sensitive information from affected installations of Microsoft Windows.