CVE-2026-32222 is an untrusted pointer dereference vulnerability in the Windows Win32K ICOMP component that allows an authorized local attacker to achieve privilege escalation. The flaw affects Windows systems where a user with standard privileges could exploit the memory handling issue to gain elevated access. The vulnerability carries a CVSS score of 7.8 (HIGH) with a local attack vector, low complexity, and low privilege requirements. Impact is significant across confidentiality, integrity, and availability, enabling attackers to read sensitive data, modify system files, and disrupt operations once privileges are elevated. Currently, CVE-2026-32222 shows no signs of active exploitation in the wild. It is not listed on CISA's Known Exploited Vulnerabilities catalog, appears inactive on threat tracking lists, and has minimal EPSS probability (0.0005) of being exploited. However, the moderate FAUCET risk score of 49.0 suggests organizations should prioritize patching when updates become available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.26100.8246CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.26100.8246CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:* | ||
< 10.0.26200.8246CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.26200.8246CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:* | ||
< 10.0.28000.1836CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.