Elevation of Privilege Vulnerability in Windows Win32K by Microsoft
CVE-2026-24285
7HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 10 March 2026
What is CVE-2026-24285?
A use-after-free vulnerability exists in Windows Win32K, allowing an authorized attacker to exploit this weakness to gain elevated privileges on the affected system. Successful exploitation could enable attackers to perform actions with elevated rights that should not be accessible, compromising the integrity and confidentiality of the affected operating system.
Affected Version(s)
Microsoft Office for Android 16.0.1 < 16.0.19822.20000
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8957
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8511