ZDI-CAN-31479: ZDI-26-541: (Pwn2Own) Microsoft Windows win32kfull Use-After-Free Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-65775.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-31479?
The severity of ZDI-CAN-31479 is rated at 8.8 according to the CVSS.
How do I fix ZDI-CAN-31479?
To fix ZDI-CAN-31479, ensure that you have the latest security updates installed for Microsoft Windows.
Who is affected by ZDI-CAN-31479?
ZDI-CAN-31479 affects installations of Microsoft Windows that have not been patched against this vulnerability.
What type of vulnerability is ZDI-CAN-31479?
ZDI-CAN-31479 is a local privilege escalation vulnerability due to a use-after-free error in win32kfull.
How can an attacker exploit ZDI-CAN-31479?
An attacker can exploit ZDI-CAN-31479 by executing low-privileged code on a vulnerable Microsoft Windows system.