ZeroHour

CVE-2026-70283

mass

Local Privilege Escalation in Microsoft Windows Win32K (Incorrect Authorization)

CVSS 3.1
7.0 high
EPSS
<1%p13
Published
()
Modified
AI analysis

CVE-2026-70283 is an incorrect authorization flaw (CWE-863) in Windows Win32K, the kernel-mode driver suite that implements the Windows graphical user interface, where an access-check weakness allows an already-authenticated, low-privileged user to gain elevated privileges on the local machine. Triggering it requires a local attacker to drive a Win32K syscall/GDI code path that mishandles the authorization check; the high attack-complexity score (AC:H) indicates exploitation depends on conditions that are difficult to predict, and no user interaction is required. A successful attacker escalates from their current user context to higher (typically SYSTEM-level) privileges, gaining high-impact confidentiality, integrity, and availability access on the compromised host. All Windows editions shipping the Win32K component are in scope — effectively every Windows client desktop and most Windows Server configurations, with Microsoft's advisory being the authoritative list of affected versions. As of this dashboard entry there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a ~0.2% (13th percentile) probability of exploitation within 30 days, so no in-the-wild exploitation is known.

What to do: Apply Microsoft's security update for CVE-2026-70283 through the standard cumulative/quality update channel and confirm your Windows version against the affected-products list in Microsoft's advisory. Prioritize machines where untrusted or multiple local users log on (workstations, terminal/RDS hosts) and keep end users running without administrative rights to limit LPE impact; given the high attack complexity and low EPSS, remediation within the regular patch cycle rather than emergency maintenance is reasonable.

Affected
Microsoft Windows (Win32K kernel driver / GUI subsystem)
Estimated exposure
mass>1 billion Windows endpoints (Win32K ships on effectively all Windows client installs) — Win32K is a core kernel component backing the Windows GUI and is present on essentially every Windows client installation, so exposure tracks the overall Windows installed base (~1.4 billion active devices per public usage statistics),…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally.

Weakness
CWE-863
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.