{"id":"CVE-2026-40369","title":"Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.","summary":"Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-822"],"published":"2026-05-12","updated":"2026-06-26","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-40369","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40369","label":"secure@microsoft.com"}],"tags":["nvd","exploit-available"],"epss":0.04725,"epssPercentile":0.9144,"ingestedAt":"2026-06-26T16:43:13.641Z","exploits":{"github":6,"githubRepos":["https://github.com/orinimron123/CVE-2026-40369-EXPLOIT","https://github.com/piffd0s/ntoskrnl-metadata","https://github.com/0xBlackash/CVE-2026-40369"],"checkedAt":"2026-09-24T07:53:03.099Z"},"exploitAvailable":true,"slug":"CVE-2026-40369","body":"## Overview\n\nHeap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":56,"depthScoreParts":{"impact":42.9,"likelihood":0.9,"exploitation":12,"ransomware":0},"changes":[{"seq":5174,"id":"CVE-2026-40369","ts":1788887251469,"field":"exploit_available","old":"false","new":"true"},{"seq":4057,"id":"CVE-2026-40369","ts":1788886367406,"field":"exploit_available","old":"true","new":"false"},{"seq":2848,"id":"CVE-2026-40369","ts":1788883034017,"field":"exploit_available","old":"false","new":"true"},{"seq":1877,"id":"CVE-2026-40369","ts":1788882436925,"field":"exploit_available","old":"true","new":"false"},{"seq":974,"id":"CVE-2026-40369","ts":1788881871211,"field":"exploit_available","old":"false","new":"true"}]}