CVE-2026-62798
Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.
CVSS
5.5
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 11 ago 2026 · Última mod.: 11 ago 2026 · CWE-822
Sin historial EPSS suficiente todavía.
Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-688107.8 ALT—
———Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.5hCVE-2026-649107.8 ALT—
———Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.5hCVE-2026-627377.8 ALT—
———Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.5hCVE-2026-613605.5 MED—
———Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.5hCVE-2026-8917——
——0Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbitrary memory address, potentially leading to privilege escalation.
Refer to the '
Security Update for ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and Armoury Crate Security Bulletin ' section on the ASUS Security Advisory for more information.19hCVE-2026-451987.8 ALT2.1%
——1Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory.
The GPU thread of control (Firmware) uses a pointer from non-secure memory belonging to the Rich Execution Environment (REE) when saving or retrieving internal data between the tightly coupled private memory to main memory. An attacker with control over the REE kernel may modify the pointer value, corrupting the data used by the GPU Firmware.4d