VulnerabilitiesApr 22, 2026
WHQL-signed Windows kernel driver that hands any user-mode caller an arbitrary memory read primit...
WHQL-signed Windows kernel driver exposes arbitrary memory read primitive to user-mode processes.
Vendor Watch
Run Microsoft?
Get an email when a reviewed story names Microsoft, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
A Windows kernel driver signed by Microsoft's WHQL certification has been discovered to expose an arbitrary memory read primitive accessible to any user-mode caller without ACL restrictions. The vulnerability allows attackers to read kernel memory and extract credentials from LSASS, making it particularly dangerous for credential theft attacks. The driver exposes the kernel page-table root, effectively bypassing security boundaries.
Entities
Microsoft (vendor)Windows Kernel (technology)WHQL (technology)