CVE-2026-24285 PUBLISHED

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

EPSS 0.05% · 14.0th percentile

Risk Scores

EPSS Score
0.05%
14.0th percentile

Affected Products

VendorProductVersions
microsoftoffice0, 0, 0
microsoftwindows_server_2022_23h20, 0, 0
microsoftwindows_server_20190, 0, 0
microsoftwindows_server_20250, 0, 0
microsoftwindows_11_25h20, 0, 0
microsoftwindows_11_23h20, 0, 0
microsoftwindows_10_22h20, 0, 0
microsoftwindows_server_20220, 0, 0
microsoftwindows_10_16070, 0, 0
microsoftwindows_server_20160, 0, 0
microsoftwindows_server_2012r2, r2, r2
microsoftwindows_10_18090, 0, 0
microsoftwindows_10_21h20, 0, 0
microsoftwindows_11_24h20, 0, 0

Timeline

References

…and 40 more

Open in Interactive Console →