
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32222 is an untrusted pointer dereference vulnerability in Windows Win32K - ICOMP that allows an authenticated local attacker to elevate privileges. It was disclosed on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday security updates. Affected products include Windows 11 versions 24H2, 25H2, and 26H1 (x64 and ARM64), as well as Windows Server 2025. The vulnerability carries a CVSS v3.1 base score of 7.8 (High), assigned by Microsoft (Microsoft MSRC, GitHub Advisory).
The root cause is classified as CWE-822 (Untrusted Pointer Dereference), where the Win32K kernel subsystem's ICOMP component obtains a value from an untrusted source, converts it to a pointer, and dereferences it without adequate validation. The attack vector is local, requiring low privileges and no user interaction, making it exploitable by any authenticated user on the affected system. Successful exploitation of this kernel-level flaw can allow an attacker to manipulate memory in ways that lead to privilege escalation, consistent with CAPEC-129 (Pointer Manipulation) (Microsoft MSRC, GitHub Advisory).
Successful exploitation allows an authenticated local user to elevate privileges to administrative or SYSTEM-level access, resulting in full system compromise. This grants the attacker high confidentiality, integrity, and availability impact — enabling access to sensitive data, modification of system configurations, and potential disruption of services. In environments where attackers have already gained a foothold (e.g., via phishing or initial access), this vulnerability could serve as a critical step for lateral movement or persistence (Microsoft MSRC, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Microsoft MSRC). The EPSS score is approximately 0.044–0.057%, placing it in the 18th percentile for exploitation likelihood within 30 days (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Microsoft released patches on April 14, 2026, as part of the April 2026 Patch Tuesday update cycle. Organizations should update affected systems to the following minimum build versions: Windows 11 24H2 (10.0.26100.8246), Windows 11 25H2 (10.0.26200.8246), Windows 11 26H1 (10.0.28000.1836), and Windows Server 2025 (10.0.26100.32690). As a complementary measure, enforce the principle of least privilege for user accounts and restrict local interactive access to sensitive systems where feasible (Microsoft MSRC, Sophos Blog).
Sophos covered CVE-2026-32222 as part of their April 2026 Microsoft Patch Tuesday analysis, noting it among the high-severity vulnerabilities requiring prompt attention (Sophos Blog). NSFOCUS also flagged it in their high-risk vulnerability notice for Microsoft's April security update (NSFOCUS Advisory). General community sentiment reflects routine patch prioritization given the absence of public exploits, with no extraordinary alarm raised.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."