PT-2026-40204 · Microsoft · Windows Kernel+1

Published

2026-05-12

·

Updated

2026-05-24

·

CVE-2026-40369

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows 11 versions 24H2 through 25H2 Windows Server 2025 (affected versions not specified)
Description An untrusted pointer dereference in the Windows Kernel allows an authorized attacker to elevate privileges locally to SYSTEM. The issue exists within the ExpGetProcessInformation() function in ntoskrnl.exe. When the NtQuerySystemInformation API endpoint is called with info class 253 and a length argument of zero, the ProbeForWrite guard is bypassed. This allows a caller-supplied kernel address to be used, enabling a deterministic arbitrary increment of kernel memory addresses. This primitive is reachable from unprivileged processes, including browser renderer sandboxes such as Chrome, Edge, and Firefox.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Untrusted Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2026-06638
CVE-2026-40369

Affected Products

Windows
Windows Kernel