CVE-2024-21346
Win32k Elevation of Privilege Vulnerability
CVSS
7.8
Alto
EPSS
4.1%
p90
KEV
—
Exploit Today
27
0-100
Publicado: 13 feb 2024 · Última mod.: 10 ago 2026 · CWE-822
4.1%EPSS · 30 días4.1%
2026-07-162026-08-12
Win32k Elevation of Privilege Vulnerability
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-688107.8 ALT23.5%
——7Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.19hCVE-2026-649107.8 ALT27.6%
——8Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.2dCVE-2026-627985.5 MED24.5%
——7Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.18hCVE-2026-627377.8 ALT27.0%
——8Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.18hCVE-2026-613605.5 MED32.7%
——10Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.22hCVE-2026-8917—1.7%
——1Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbitrary memory address, potentially leading to privilege escalation.
Refer to the '
Security Update for ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and Armoury Crate Security Bulletin ' section on the ASUS Security Advisory for more information.2d