CVE-2026-33840Disclosure(microsoft / windows_11_24h2)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_11_24h2
  • windows_11_25h2
  • windows_11_26h1
  • windows_server_2025

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-05-12); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2025

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Mentions · 2026-05-15: 1PoC Mentioned / Linked · 2026-05-12: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 105-1205-1305-1405-15
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-121
Disclosure1
2026-05-131
General1
2026-05-141
Disclosure1
2026-05-151
Disclosure1
Full discourse4 posts
  • STEALIEN@stealien
    Disclosure

    스틸리언 Diffuto, Microsoft CVE 발급 https://blog.naver.com/stealien_official/224285210948 #Diffuto #AI보안 #CVE #Microsoft #사이버보안 CVE-2026-33840 / CVSS 7.8 HIGH / Win32K EoP 식별부터 재현까지 전 과정을 AI를 통해서 진행하였으며, 연구원은 최종 검증만 진행했습니다. 스틸리언은 AI와 자동화를 활용한 보안 기술 연구를 지속하고 있습니다👽

    Post summary

    Stealien announced Microsoft CVE‑2026‑33840, providing its CVSS score and Win32K EoP classification, but offered no PoC, exploit code, or mitigation details.

    02141393
    510 followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft ●悪用可能性 -悪用の事実を確認済み:0 件 -悪用される可能性が高い:13 件 ・CVE-2026-33835 7.8 Windows Cloud Files Mini Filter Driver ・CVE-2026-33837 7.8 Windows TCP/IP ・CVE-2026-33840 7.8 Windows Win32K: ICOMP つづく… https://x.com/kawn2020/status/2054357169261490453

    Post summary

    The tweet lists several CVEs with high exploitation likelihood, but provides no evidence of active attacks, PoC, or remediation, making it a general threat notice.

    1000098
    85 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-33840 | Microsoft Windows 11 24H2/11 25H2/11 26H1/Server 2025 Win32k use after free (WID-SEC-2026-1489) https://ift.tt/4ncmugC A vulnerability, which was classified as critical, was found in Microsoft Windows 11 24H2/11 25H2/11 26H1/Server 2025. This affects an unknow…

    Post summary

    A critical Win32k use‑after‑free vulnerability (CVE‑2026‑33840) in Windows 11 and Server 2025 has been disclosed, with no evidence of active exploitation or patch information.

    0000083
    974 followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🪟 CVE-2026-33840 is the Win32k “oops we freed the memory early” bug… and it lands you SYSTEM. Important my foot—this is the kind of slip that turns PCs into fireworks. #Windows #Security https://windowsforum.com/threads/cve-2026-33840-win32k-use-after-free-local-privesc-to-system-in-windows-11.417714/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #Win32KVulnerability #LocalPrivilegeEscalation https://t.co/CBttPCTJt7

    Post summary

    The post reveals a new Windows Win32k use‑after‑free privilege escalation bug (CVE‑2026‑33840) that can grant SYSTEM privileges, linking to a forum thread for additional details.

    0000039
    1.1K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2025---

Explore more