Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Local Privilege Escalation in Windows dxgkrnl Driver (CVE‑2026‑50375)

A TOCTOU flaw in the Windows dxgkrnl.sys driver (CVE‑2026‑50375) enables a low‑privileged user to obtain SYSTEM rights. The high‑severity bug underscores the need for continuous vulnerability‑management and audit‑ready remediation evidence.

LiveThreat™ Intelligence · 📅 October 02, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
zerodayinitiative.com

Critical Local Privilege Escalation in Windows dxgkrnl Driver (CVE‑2026‑50375)

What It Is — A Time‑Of‑Check‑Time‑Of‑Use (TOCTOU) flaw in the dxgkrnl.sys kernel driver allows a low‑privileged user to gain SYSTEM‑level rights on Windows machines. The issue stems from missing proper locking when the driver manipulates internal objects.

Exploitability — The vulnerability is publicly disclosed with a CVSS 8.8 (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). No public exploit code has been released, but the low attack complexity and high impact make it trivially exploitable once an attacker can run any code as a standard user.

Affected Products — Microsoft Windows (all supported editions that include the dxgkrnl.sys driver).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous vulnerability‑management controls that capture patch status in real time.
  • Provides audit‑ready evidence that a organization is actively monitoring and remediating high‑severity kernel bugs, a key trust signal for customers and regulators.
  • Highlights the importance of mapping this finding to a control objective (e.g., “Maintain a robust vulnerability‑remediation process”) that satisfies multiple frameworks such as NIST CSF 2.0, ISO 27001, and SOC 2.

Recommended Actions

  • Deploy Microsoft’s security update for CVE‑2026‑50375 immediately across all Windows endpoints.
  • Verify patch deployment via an automated asset‑inventory scan and retain the scan logs as evidence of remediation.
  • Update your vulnerability‑management policy to include kernel‑driver checks and ensure continuous monitoring for future TOCTOU bugs.
  • Document the remediation workflow in your Trust Center to provide a defensible audit trail.

Source: Zero Day Initiative Advisory ZDI‑26‑751

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-751/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →