Windows Kernel Flaw Lets Attackers Modify Memory Counters
ID: 018618df-1cf9-5854-9854-7c706369f4fb
STIX ID: report--018618df-1cf9-5854-9854-7c706369f4fb
Feed Name: Cyber Press
Threat Score
A critical Windows kernel vulnerability (CVE-2026-40369) in ExpGetProcessInformation (ntoskrnl.exe) triggered by NtQuerySystemInformation class 253 allows an unprivileged process — including sandboxed browser renderers — to deterministically escalate to NT AUTHORITY\SYSTEM via an arbitrary kernel-address increment primitive; a complete five-stage exploit and public PoC were released, Microsoft issued a patch on May 12, 2026, and affected Windows 11 builds remain at risk until updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
