Kernel Vulnerability
The latest Kernel Vulnerability coverage — news, analysis, and updates from the WindowsNews.AI desk.
AFD.sys flaw lets attackers elevate to SYSTEM across multiple Windows builds, CVE-2026-21236.
Microsoft has disclosed a significant security vulnerability in the Windows operating system kernel that could allow attackers to gain elevated privileges on affected systems. Designated as...
Microsoft Warns of High-Confidence Win32k Bug That Hands Attackers SYSTEM Access—Patch Now
Microsoft on Tuesday posted CVE-2026-20870 to its Security Update Guide, a local privilege escalation vulnerability in the Windows Win32 kernel subsystem that the company has confirmed with “high...
CVE-2026-20857: Windows OneDrive Component Flaw Grants Attackers System-Level Access — Update Now
Microsoft has released a security fix for a privilege escalation vulnerability in the Windows Cloud Files Mini Filter driver, the kernel‑mode engine behind OneDrive’s on‑demand file...
CVE-2026-20860: Critical afd.sys Kernel Vulnerability Threatens Windows Security
Microsoft has disclosed a significant security vulnerability in the Windows operating system that could allow attackers to gain elevated privileges on affected systems. Designated as CVE-2026-20860,...
CVE-2026-20859: Critical Windows Kernel Driver EoP Vulnerability Requires Immediate Patching
Microsoft has issued a critical security alert for CVE-2026-20859, a newly discovered elevation of privilege (EoP) vulnerability in a Windows kernel-mode driver that poses significant operational...
CVE-2026-20831: Critical Windows AFD Kernel Vulnerability Threatens Local Privilege Escalation
Microsoft has disclosed a critical kernel-level elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys), designated as CVE-2026-20831, that enables...
Windows AFD Driver Vulnerability Lets Attackers Seize SYSTEM Control—Patch Now
Microsoft has patched a privilege escalation flaw in the Windows Ancillary Function Driver (AFD) that could allow an attacker with local access to gain SYSTEM-level control of an unpatched machine....
Microsoft Flags Kernel Bug in Azure Linux; WSL2 Status Still Unknown
{ "title": "Microsoft Flags Kernel Bug in Azure Linux; WSL2 Status Still Unknown", "content": "Microsoft’s security team has confirmed that CVE-2025-38499, a recently disclosed flaw in the...
CVE-2025-68343: Linux Kernel GS_USB Driver Vulnerability Explained
A critical vulnerability in the Linux kernel's GS_USB CAN bus driver has been identified and assigned CVE-2025-68343, representing a significant security concern for systems using Controller Area...
CVE-2025-68733: Smack LSM Vulnerability Exposes Linux Systems to Unprivileged Relabeling Attacks
A critical vulnerability in the Smack Linux Security Module (LSM) has been assigned CVE-2025-68733, exposing systems to potential privilege escalation and security bypass attacks. The flaw,...
CVE-2025-38275 Azure Linux Vulnerability: Scope, Impact, and Microsoft's Response
Microsoft has confirmed that Azure Linux images contain the upstream open-source kernel code referenced by CVE-2025-38275, making them potentially affected by this security vulnerability. The...
CVE-2025-38225: Azure Linux Vulnerability & Microsoft's VEX Attestation Strategy
Microsoft's recent security advisory for CVE-2025-38225 reveals more than just another Linux kernel vulnerability—it showcases the company's evolving approach to vulnerability disclosure through...