logo

Windows Kernel Bug Exploits Browser Sandboxes

ID: 1e694ef1-5ad7-58eb-b2b4-f7fc511630ba

STIX ID: report--1e694ef1-5ad7-58eb-b2b4-f7fc511630ba

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Ddos

...
...

Microsoft patched a Windows Kernel local elevation-of-privilege vulnerability (CVE-2026-40369) that allows untrusted pointer dereference in nt!ExpGetProcessInformation via NtQuerySystemInformation leading to arbitrary kernel writes and sandbox escapes (affecting Windows 11 24H2–25H2). Public technical details and proof-of-concept exploit code have been published on a researcher’s blog and GitHub, increasing the risk of local automated attacks; organizations are advised to apply Microsoft’s May patch and monitor for unusual kernel-mode writes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.