
CVE-2026-40369
Windows Kernel Heap-Based Buffer Overflow allowing local attackers to elevate privileges to NT AUTHORITY\SYSTEM.
CVE-2026-40369 is a High Severity privilege escalation vulnerability affecting Microsoft Windows Kernel components.
The vulnerability originates from an unsafe memory operation within the Windows Kernel and may allow an authenticated attacker with low privileges to gain SYSTEM-level privileges on a vulnerable host. Microsoft assigns a CVSS v3.1 score of 7.8 (High). :contentReference[oaicite:0]{index=0}
Successful exploitation may allow an attacker to:
Affected confidentiality, integrity and availability impacts are all rated High. :contentReference[oaicite:1]{index=1}
Affected versions include releases prior to Microsoft's security updates published in May 2026. :contentReference[oaicite:2]{index=2}
Attacker obtains low-privileged access
│
▼
Executes crafted local payload
│
▼
Triggers vulnerable Kernel code
│
▼
Memory corruption occurs
│
▼
Privileges elevated to SYSTEM
│
▼
Full machine compromise
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
:contentReference[oaicite:3]{index=3}
Monitor for:
4672 - Special Privileges Assigned
4688 - New Process Creation
4624 - Logon Events
4697 - Service Installation
7045 - New Service Creation
:contentReference[oaicite:4]{index=4}
title: Possible Windows Privilege Escalation Activity
id: 8b7f4a89-40369-eop
status: experimental
logsource:
product: windows
detection:
selection:
EventID:
- 4672
- 4688
condition: selection
level: high
The CVE was initially described as an untrusted pointer dereference and later updated by Microsoft/NVD as a heap-based buffer overflow in the Windows Kernel. :contentReference[oaicite:5]{index=5}
This repository is intended for:
Do NOT use this information against systems without explicit authorization.
| Field | Value |
|---|
| CVE | CVE-2026-40369 |
| Vendor | Microsoft |
| Severity | High |
| CVSS | 7.8 |
| CWE | CWE-822 |
| Attack Vector | Local |
| User Interaction | None |
| Privileges Required | Low |
| Impact | Privilege Escalation |
| Exploitation | Local Authenticated Access |
| Metric | Value |
|---|
| Attack Vector | Local |
| Attack Complexity | Low |
| Privileges Required | Low |
| User Interaction | None |
| Scope | Unchanged |
| Confidentiality | High |
| Integrity | High |
| Availability | High |
| Category | Value |
|---|
| Vulnerability Type | Heap-Based Buffer Overflow |
| CWE | CWE-822 |
| Component | Windows Kernel |
| Authentication Required | Yes |
| Remote Exploitable | No |
| Privilege Escalation | Yes |
| Severity | High |
| CVSS | 7.8 |