An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 78.00 |
| Exploitation signal(KEV listed) | ×1.50 |
| Ransomware bonus | +5.00 |
| VPI | 100.00 |
VPI formula vpi-v1
Required Action
Apply updates per vendor instructions.
This CVE is referenced in a KISA security bulletin (Korean only).
| Source | CVSS Version | Base Score | Severity | Vector String | Assessment Date |
|---|---|---|---|---|---|
| NVDNIST | 3.1 | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 04/20/2026 |
| NVDNIST | 2.0 | 7.2 |
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
| AV:L/AC:L/Au:N/C:C/I:C/A:C |
| 04/20/2026 |