Information disclosure in Microsoft Windows and Windows Server - CVE-2026-56184
Published: July 17, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in Windows Win32K when handling local access to kernel memory addresses. A local user can access disclosed kernel memory address information to disclose sensitive information.
The disclosed information may include certain memory addresses within kernel space, which could be leveraged for other malicious activities.
Affected software
Windows Server
How to mitigate CVE-2026-56184
Windows Server - addressed in versions 2012 R2 6.3.9600.23291, 2022 10.0.20348.5386, 2025 10.0.26100.33158