PT-2026-40204 · Microsoft · Windows Kernel+1
Published
2026-05-12
·
Updated
2026-05-24
·
CVE-2026-40369
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows 11 versions 24H2 through 25H2
Windows Server 2025 (affected versions not specified)
Description
An untrusted pointer dereference in the Windows Kernel allows an authorized attacker to elevate privileges locally to SYSTEM. The issue exists within the
ExpGetProcessInformation() function in ntoskrnl.exe. When the NtQuerySystemInformation API endpoint is called with info class 253 and a length argument of zero, the ProbeForWrite guard is bypassed. This allows a caller-supplied kernel address to be used, enabling a deterministic arbitrary increment of kernel memory addresses. This primitive is reachable from unprivileged processes, including browser renderer sandboxes such as Chrome, Edge, and Firefox.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Untrusted Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows Kernel