ThreatCluster

Critical Windows Kernel Vulnerability Enables SYSTEM Privilege Escalation

First seen 27 May 2026, 15:27 UTC GbhackersCybersecuritynews 93% similarity 69

Article Content

Browse articles
ThreatCluster

A critical vulnerability in the Windows kernel, identified as CVE-2026-40369, has been disclosed, allowing unprivileged processes to escalate privileges to SYSTEM level. This flaw affects Windows 11 versions 24H2 through 25H2 and resides in the ntoskrnl.exe component, specifically within the ExpGetProcessInformation function. Attackers can exploit this vulnerability from restricted environments, such as browser sandboxes, using a single NtQuerySystemInformation call. The vulnerability was published on May 12, 2026, with a proof of concept (PoC) made public shortly after on May 14, 2026. Security researchers have emphasized the potential for widespread exploitation given the ease of access to the attack vector. Organizations using affected Windows versions are urged to apply security updates as soon as they are available.

Key Points: • CVE-2026-40369 allows unprivileged processes to escalate to SYSTEM privileges. • The vulnerability affects Windows 11 versions 24H2 through 25H2. • Exploitation can occur from browser sandboxes using a single API call.

ThreatCluster AI

Timeline

2026-05-12
CVE-2026-40369 published
A critical Windows kernel vulnerability was officially disclosed, affecting Windows 11.
Gbhackers
2026-05-14
First public PoC released
A proof of concept for the vulnerability was made public, increasing the risk of exploitation.
Gbhackers
2026-05-27
Vulnerability reported in news articles
Multiple cybersecurity outlets reported on the critical nature of CVE-2026-40369, highlighting its impact.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story