HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Use‑After‑Free in Windows win32kfull Driver (CVE‑2026‑65775) Enables Local Privilege Escalation

A use‑after‑free flaw in the Windows win32kfull driver (CVE‑2026‑65775) allows a low‑privileged process to gain SYSTEM rights. The vulnerability scores 8.8 on CVSS and underscores the need for robust access‑control and patch‑management practices to meet SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 August 12, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Critical Use‑After‑Free in Windows win32kfull Driver (CVE‑2026‑65775) Enables Local Privilege Escalation

What It Is — A use‑after‑free flaw in the win32kfull.sys driver allows a low‑privileged process to execute arbitrary code as SYSTEM. The vulnerability stems from the driver not validating an object’s existence before operating on it.

Exploitability — Publicly disclosed via the Pwn2Own competition; proof‑of‑concept demonstrated. No known wild‑type exploits yet, but the CVSS 8.8 rating (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) indicates high ease of exploitation once code execution is achieved locally.

Affected Products — Microsoft Windows (all supported versions that include the vulnerable win32kfull.sys driver).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access Controls – The flaw bypasses OS‑level isolation, highlighting the need for strict least‑privilege policies and continuous verification that privileged accounts are protected.
  • Patch Management Evidence – Demonstrates the importance of timely patch deployment and retaining verifiable records of remediation to satisfy the Security and Availability criteria of SOC 2.
  • Continuous Monitoring – Real‑time detection of unpatched endpoints becomes a critical control to prove due diligence during audits.

Recommended Actions

  • Deploy Microsoft’s security update for CVE‑2026‑65775 immediately across all Windows endpoints.
  • Verify patch rollout via automated inventory tools and retain logs as audit evidence.
  • Review and tighten local admin privileges; enforce “least‑privilege” configurations on workstations.
  • Incorporate the patch status into your continuous compliance dashboard to demonstrate ongoing control effectiveness.

Source: Zero Day Initiative Advisory – ZDI‑26‑541

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-541/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →