Use‑After‑Free in Windows win32kfull Driver (CVE‑2026‑65776) Enables Local Info Disclosure and Privilege Escalation
What It Is — A use‑after‑free flaw in the win32kfull.sys driver allows a low‑privileged process to read kernel memory. The vulnerability can be chained with other local bugs to gain SYSTEM privileges.
Exploitability — Local‑only; requires attacker‑controlled code execution. No public exploit code, but the CVSS 6.5 rating (AV:L/AC:L/PR:L) reflects low attack complexity.
Affected Products — Microsoft Windows (all supported versions that include the win32kfull driver).
Why It Matters for Compliance & Audit Readiness
- Demonstrates the need for continuous control mapping: the flaw bypasses OS‑level isolation, a key control in SOC 2 CC6.1 (System Operations).
- Patch management evidence must be captured in real time to prove due‑diligence during audits.
- A single unpatched endpoint can invalidate the organization’s overall security posture, affecting the “Security” principle of SOC 2.
Recommended Actions
- Deploy Microsoft’s security update for CVE‑2026‑65776 immediately across all Windows endpoints.
- Verify patch rollout with automated inventory tools and retain deployment logs as audit evidence.
- Map the vulnerability to SOC 2 CC6.1 and CC7.1 controls, documenting remediation steps in your continuous compliance platform.
Source: Zero Day Initiative advisory