ZDI-26-541: (Pwn2Own) Microsoft Windows win32kfull Use-After-Free Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-65775.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-541?
The severity of ZDI-26-541 is rated at CVSS 8.8, indicating a high risk for privilege escalation.
How do I fix ZDI-26-541?
To fix ZDI-26-541, ensure that your Microsoft Windows installation is updated with the latest security patches provided by Microsoft.
What type of vulnerability is ZDI-26-541?
ZDI-26-541 is a use-after-free vulnerability that allows local privilege escalation in Microsoft Windows.
Who is affected by ZDI-26-541?
ZDI-26-541 affects installations of Microsoft Windows where local attackers can exploit the vulnerability.
Can ZDI-26-541 be exploited remotely?
No, ZDI-26-541 requires that an attacker first execute low-privileged code on the target system.