Microsoft Win32k Elevation of Privilege Vulnerabilities Disclosed
Microsoft published security advisories for two Win32k Elevation of Privilege flaws, tracked as CVE-2023-36011 and CVE-2024-43636, in its Security Update Guide. Both issues affect the Windows Win32k subsystem, a core component involved in graphical and kernel-level operations, and successful exploitation could allow an attacker to gain elevated privileges on a targeted system.
The advisories indicate that Microsoft addressed the vulnerabilities through security updates and added them to its official guidance portal for customer remediation. Organizations running affected Windows systems should review the relevant Microsoft advisories, verify patch deployment, and prioritize remediation because privilege-escalation flaws in Win32k are commonly valuable for post-compromise activity and local escalation chains.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft publishes advisory for CVE-2024-43636 Win32k EoP flaw
Microsoft released a Security Update Guide advisory for CVE-2024-43636, another Win32k Elevation of Privilege vulnerability.
Microsoft publishes advisory for CVE-2023-36011 Win32k EoP flaw
Microsoft released a Security Update Guide advisory for CVE-2023-36011, a Win32k Elevation of Privilege vulnerability.
Sources
2 references tracked. Mallory keeps watching after this page renders.
CVE-2024-43636 - Security Update Guide - Microsoft - Win32k Elevation of Privilege Vulnerability
msrc.microsoft.com
Open sourceCVE-2023-36011 - Security Update Guide - Microsoft - Win32k Elevation of Privilege Vulnerability
portal.msrc.microsoft.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


