Remote Code Execution Vulnerability in Windows Kernel-Mode Drivers by Microsoft
CVE-2026-34332

8HIGH

What is CVE-2026-34332?

A vulnerability has been identified in Windows Kernel-Mode Drivers that allows an attacker with valid authorization to execute arbitrary code remotely. This occurs due to a use after free condition which could potentially lead to sensitive system actions being compromised. It is crucial for users and administrators to be aware of this issue and apply the necessary patches to mitigate any risks associated with this vulnerability.

Affected Version(s)

Windows Server 2025 (Server Core installation) x64-based Systems 10.0.26100.0 < 10.0.26100.32860

Windows Server 2025 x64-based Systems 10.0.26100.0 < 10.0.26100.32860

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.