Windows Kernel Vulnerability Allows Attackers to Modify Kernel Memory Counters
ID: 4d5ca8f4-c20a-5dea-baf3-2bdb54614eac
STIX ID: report--4d5ca8f4-c20a-5dea-baf3-2bdb54614eac
Feed Name: cybersecurityNews.com
**Executive Summary:** A critical, deterministic Windows kernel vulnerability (CVE-2026-40369) in ntoskrnl.exe's ExpGetProcessInformation via NtQuerySystemInformation (info class 253) allows unprivileged processes — including sandboxed browser renderers — to bypass ProbeForWrite validation and increment arbitrary kernel memory, enabling reliable SYSTEM privilege escalation, KASLR bypass, and subsequent token manipulation; no official patch had been confirmed at publication, and organizations are advised to monitor NtQuerySystemInformation usage and implement detection rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
