CVE-2026-50416
LOWMicrosoft Windows Win32K - Local Information Disclosure
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2026-50416. PoCs published by karollooool.
AI-analyzed exploit summary This repository provides a detailed proof-of-concept for CVE-2026-50416, a KASLR bypass vulnerability in Windows 11 (Insider Build 10.0.28020.2134) via a kernel address leak in the desktop heap. The exploit demonstrates reading a kernel pointer from user-mode without privileges, enabling reliable kernel exploitation.
Description
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.
Exploits (1)
This repository provides a detailed proof-of-concept for CVE-2026-50416, a KASLR bypass vulnerability in Windows 11 (Insider Build 10.0.28020.2134) via a kernel address leak in the desktop heap. The exploit demonstrates reading a kernel pointer from user-mode without privileges, enabling reliable kernel exploitation.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N