Skip to content

Windows Kernel Vulnerability Lets Attackers Modify Kernel Memory Counters

Gbhackers Divya May 27, 2026

A critical Windows kernel vulnerability, CVE-2026-40369, allows any unprivileged process, including a browser renderer sandbox, to increment arbitrary kernel memory and reliably escalate to SYSTEM on Windows 11 24H2–25H2. The bug sits in ntoskrnl.exe inside ExpGetProcessInformation, reachable via a single NtQuerySystemInformation call with information class 253. Windows Kernel Vulnerability CVE-2026-40369 is described as an untrusted pointer dereference in the Windows […]

Extracted Entities

Attack Types (1)

Platforms (1)