logo

Windows Kernel Vulnerability Lets Attackers Modify Kernel Memory Counters

ID: 95fb32ef-c4b8-50df-9e45-bed80d524980

STIX ID: report--95fb32ef-c4b8-50df-9e45-bed80d524980

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Divya

...
...

CVE-2026-40369 is a Windows 11 (24H2–25H2) kernel vulnerability in ExpGetProcessInformation reachable via NtQuerySystemInformation class 253 that permits an attacker-controlled 12-byte kernel increment primitive, enabling reliable local privilege escalation from unprivileged or sandboxed processes (including browser renderers); public exploits are available and Microsoft patched the flaw in May 2026, with guidance to deploy updates and monitor for post-exploitation behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.