CVE-2026-34332Disclosure(microsoft / windows_server_2025)

LOWCVSS 8.0 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_server_2025 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_server_2025

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-05-15)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
windows_server_2025

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-12: 1Mentions · 2026-05-15: 2Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-15: 205-1205-15
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-121
Patch1
2026-05-152
Disclosure2
Full discourse3 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🚨تحديثات مايكروسوفت لشهر مايو 2026 قفلت مجموعه من الثغرات الخطيرة على المستخدمين العاديين و المنظمات ملخص الثغرات المهمه من وجهه نظري 📍CVE-2026-41089 في Windows Netlogon التقييم: 9.8 ثغرة RCE قبل المصادقة في Netlogon. خطورتها عالية جداً لأنها تسهل استهداف Domain Controllers، وقد تسمح بتنفيذ كود بصلاحيات عالية بدون حساب مسبق إذا توفرت شروط الاستغلال. هذي اهم ثغره ولازم تعطيها اولولية حالياً 📍CVE-2026-41096 في Windows DNS Client التقييم: 9.8 ثغرة Heap-based buffer overflow في dnsapi.dll. المهاجم قد يستغلها عبر استجابة لطلب DNS خبيث لتنفيذ كود عبر الشبكة. السيناريو الأخطر يظهر إذا قدر يتحكم في مسار DNS أو يستخدم DNS server خبيث أو هجمات Man-in-the-Middle 📍CVE-2026-42898 في Dynamics 365 On-Premises التقييم: 9.9 ثغرة RCE في Dynamics 365 On-Premises خلل في التحكم بعملية توليد الكود داخل Microsoft Dynamics 365 On-Premises يسمح لمهاجم مصادق بتنفيذ كود عبر الشبكة. 📍CVE-2026-40364 في Microsoft Word التقييم: 8.4 ثغرة RCE في Word. الخطر أنها قد تُستغل عند فتح أو معاينة ملف خبيث عبر Preview Pane في بعض السيناريوهات. انتبه ياصديقي لا تركز على نظام التشغيل فقط وتنسى Office. مرفق واحد قد يكون بداية الاختراق 📍CVE-2026-35439 وCVE-2026-40365 في SharePoint Server التقييم: 8.8 ثغرات RCE في SharePoint Server. SharePoint غالباً يحتوي ملفات داخلية، صلاحيات كبيرة ، وربط مع Active Directory. استغلاله قد يعطي المهاجم فرصة للوصول للشبكة الداخلية ويفتح باب للتنقل في الشبكه ايضا. 📍CVE-2026-40370 في SQL Server التقييم: 8.8 ثغرة RCE في SQL Server، لكنها تتطلب صلاحيات منخفضة. الخطر يرتفع إذا كان الخادم مكشوفاً على الانترنت أو إذا حصل المهاجم على حساب محدود. 📍CVE-2026-40415 في Windows TCP/IP التقييم: 8.1 ثغرة RCE في Network Stack نفسه. الخطورة أنها لا تعتمد على ملف Word أو Excel أو رابط تصيد. الاستغلال يتم من خلال الشبكة من خلال حزم مصممة بطريقة معينة. 📍CVE-2026-34332 في Windows Kernel-Mode Driver التقييم: 8.0 ثغرة RCE في Kernel-Mode Driver. عالية الخطورة لأنها مرتبطة طبقة حساسة من النظام. 📍CVE-2026-40359 في Excel التقييم: 7.8 ثغرة RCE في Excel. فتح أو معاينة ملف Excel خبيث قد يؤدي إلى تنفيذ كود على جهاز الضحية. هذا النوع من الثغرات مهم لأن ملفات Office ما زالت من أكثر أدوات الهجوم استخداماً داخل المؤسسات. 📍CVE-2026-34342 في Windows Print Spooler التقييم: 7.0 ثغرة Elevation of Privilege. ليست PrintNightmare جديدة، لكنها تذكرنا أن Print Spooler ما زال سطح هجوم مهم بعد الاختراق الأولي. إذا الخدمة غير مطلوبة على بعض الخوادم، عطّلها. وإذا مطلوبة، حدثها وراقب استخدامها

    Post summary

    The post lists several high‑severity Microsoft CVEs released in May 2026, providing basic vulnerability classifications and impact descriptions, but does not supply any PoC, exploit tool, active exploitation evidence, or patch information.

    03125912.7K
    50.0K followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-34332 | Microsoft Windows Server 2025 Kernel-Mode Driver use after free (WID-SEC-2026-1489) https://ift.tt/3UzSP6n A vulnerability was found in Microsoft Windows Server 2025. It has been rated as critical. The impacted element is an unknown function of the component K…

    Post summary

    The post announces a new critical kernel-mode driver use-after-free vulnerability in Microsoft Windows Server 2025, providing some technical details but no PoC, exploit code, or patch information.

    0000068
    974 followersView on X
  • WindowsForum@windowsforum
    Patch

    🚨 CVE-2026-34332: Kernel RCE via NVMe-oF… because nothing says “secure data center” like remote storage poking kernel memory. Hotpatch or patch—either way, move fast. #Windows #Security https://windowsforum.com/threads/cve-2026-34332-windows-server-2025-kernel-rce-via-nvme-of-kb5087539.417930/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #WindowsServer2025 #Hotpatching #Cve202634332 #KernelModeDriver https://t.co/ZfXMdJ5Sfo

    Post summary

    The thread alerts to a Windows Server 2025 kernel remote code execution via NVMe‑oF and urges users to apply hotpatches or patches promptly.

    0000062
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_server_2025---

Explore more