VDB
CVE-2026-26112
CVE-2026-26112
PUBLISHED
CVSS 7.800000190734863 HIGH
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
EPSS 0.03% · 9.4th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
0.03%
9.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 10 Version 1809 | 10.0.17763.0 |
| microsoft | office_2024 | 16.0.0, 16.0.0, 16.0.0 |
| Microsoft | Windows Server 2016 (Server Core installation) | 10.0.14393.0 |
| Microsoft | Windows 10 Version 22H2 | 10.0.19045.0 |
| microsoft | windows_server_2019 | 10.0.17763.0, 10.0.17763.0 |
| Microsoft | Windows 11 version 22H3 | 10.0.22631.0 |
| microsoft | office_long_term_servicing_channel | 2021, 2024, 2024 |
| Microsoft | Microsoft Office LTSC for Mac 2024 | 16.0.0, 16.0.0, 16.0.0 |
| Microsoft | Microsoft Office 2019 | 19.0.0, 19.0.0, 19.0.0 |
| microsoft | excel_2016 | 16.0.0.0, 16.0.0.0, 16.0.0.0 |
| microsoft | 365_apps | 16.0.1, 16.0.1, 16.0.1 |
| microsoft | windows_server_23h2 | 10.0.25398.0 |
| microsoft | windows_10_21H2 | 10.0.19044.0 |
| Microsoft | Windows 11 Version 24H2 | 10.0.26100.0 |
| Microsoft | Windows 11 Version 25H2 | 10.0.26200.0 |
| Microsoft | Windows Server 2022, 23H2 Edition (Server Core installation) | 10.0.25398.0 |
| Microsoft | Windows 11 Version 23H2 | 10.0.22631.0 |
| microsoft | office_2019 | 19.0.0, 19.0.0, 19.0.0 |
| Microsoft | Windows Server 2012 (Server Core installation) | 6.2.9200.0 |
| microsoft | office | 2019, 2019, 2019 |
…and 34 more
Exploit Intelligence
- https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1 (msrc)
- Win32k Elevation of Privilege Vulnerability (circl)
- CIRCL seen: CVE-2026-24285 (circl-sighting)
- CIRCL seen: CVE-2026-24285 (circl-sighting)
- CIRCL seen: CVE-2026-24285 (circl-sighting)
- CIRCL seen: CVE-2026-24285 (circl-sighting)
- CIRCL seen: CVE-2026-26112 (circl-sighting)
- CIRCL seen: CVE-2026-26112 (circl-sighting)
- CIRCL seen: CVE-2026-26112 (circl-sighting)
- CIRCL seen: CVE-2026-26112 (circl-sighting)
…and 1 more exploits
Timeline
- Mar 10, 2026 CVE Published
- Mar 10, 2026 PoC Published
- Mar 10, 2026 PoC Published
- Mar 10, 2026 PoC Published
- Mar 11, 2026 EPSS Score
- Mar 11, 2026 PoC Published
- Mar 11, 2026 PoC Published
- Mar 11, 2026 Security Advisory
- Mar 12, 2026 EPSS Score
- Mar 13, 2026 EPSS Score
- Mar 14, 2026 EPSS Score
- Mar 15, 2026 EPSS Score
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26110 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26144 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24285 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26108 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26112 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26113 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26107 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26134 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26109 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-25180 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-26112 advisory