Critical Windows Kernel Vulnerability Enables SYSTEM Privilege Escalation
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability in the Windows kernel, identified as CVE-2026-40369, has been disclosed, allowing unprivileged processes to escalate privileges to SYSTEM level. This flaw affects Windows 11 versions 24H2 through 25H2 and resides in the ntoskrnl.exe component, specifically within the ExpGetProcessInformation function. Attackers can exploit this vulnerability from restricted environments, such as browser sandboxes, using a single NtQuerySystemInformation call. The vulnerability was published on May 12, 2026, with a proof of concept (PoC) made public shortly after on May 14, 2026. Security researchers have emphasized the potential for widespread exploitation given the ease of access to the attack vector. Organizations using affected Windows versions are urged to apply security updates as soon as they are available.
Key Points: • CVE-2026-40369 allows unprivileged processes to escalate to SYSTEM privileges. • The vulnerability affects Windows 11 versions 24H2 through 25H2. • Exploitation can occur from browser sandboxes using a single API call.