Windows Kernel CVE-2026-40369 — NtQuerySystemInformation ProbeForWrite Bypass Enables Arbitrary Kernel Memory Increment → SYSTEM LPE from Browser Sandboxes (Ori Nimron)
Windows Kernel CVE-2026-40369 (TL-2026-0604), also tracked as Ori Nimron ProbeForWrite Bypass, is a critical-severity software vulnerability scored CVSS 7.8, first published 2026-05-27. It has no confirmed attribution, affects Microsoft Windows 11 24H2, references 1 CVE (CVE-2026-40369), maps to 14 MITRE ATT&CK techniques (T1003.001, T1012, T1055), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-0604
- Threat ID
- TL-2026-0604
- Also known as
- Ori Nimron ProbeForWrite Bypass, NtQuerySystemInformation Class 253 Zero-Length Bug, ExpGetProcessInformation Increment Primitive
- Severity
- CRITICAL
- CVSS
- 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- MONITORING
- Category
- VULNERABILITY
- First published
- 2026-05-27
- Last reviewed
- 2026-05-27
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- government, financial, healthcare, technology, defense, manufacturing, education, energy, telecommunications, retail
- Target regions
- Global, North America, Europe, Asia-Pacific, Middle East, Latin America, Africa
- Detection rules
- 9
- Indicators of compromise
- 16
CVE-2026-40369 is a critical Windows kernel untrusted-pointer-dereference vulnerability (CWE-822) in ntoskrnl.exe's ExpGetProcessInformation, reachable via NtQuerySystemInformation information class 253 (SystemProcessInformationExtension). When the syscall is invoked with OutputBufferLength=0, the kernel's ProbeForWrite validation is bypassed and a user-supplied pointer is dereferenced for a write, yielding a 100%-deterministic single-syscall arbitrary kernel-memory-increment primitive. Discovered by Ori Nimron and patched on 2026-05-12, the bug affects Windows 11 24H2/25H2/26H1 and Server 2025, is not gated by Win32k lockdown or integrity-level checks, and is therefore reachable from Chrome, Edge, and Firefox renderer sandboxes — making it a high-value building block for browser-escape chains that culminate in SYSTEM-level privilege escalation.
How Windows Kernel CVE-2026-40369 works
## Overview
CVE-2026-40369 is an untrusted pointer dereference (CWE-822) in the Windows kernel's ExpGetProcessInformation routine inside ntoskrnl.exe. The vulnerability is reachable through NtQuerySystemInformation when called with SystemInformationClass=253 (SystemProcessInformationExtension) and SystemInformationLength=0. Under this specific input shape, the kernel skips its ProbeForWrite validation on the SystemInformation OUT parameter and proceeds to dereference the user-supplied pointer as a write target. Because the operation performed inside the vulnerable code path is an interlocked add/increment against a counter field, the attacker obtains a deterministic, race-free, single-syscall arbitrary-kernel-memory-increment primitive.
The issue was reported by security researcher Ori Nimron and addressed by Microsoft in the May 2026 Patch Tuesday cumulative updates (build floors: 24H2 10.0.26100.8390, 25H2 10.0.26200.8390, 26H1 10.0.28000.2113, Server 2025 10.0.26100.32772). Microsoft assigned a CVSS v3.1 base score of 7.8 (Local/Low complexity/Low privileges/No UI/High C-I-A); Threadlinqs Intelligence rates the threat CRITICAL because the syscall is not subject to Win32k lockdown, integrity-level checks, or browser sandbox policy restrictions, meaning a content-process compromise in any major browser can pivot directly through this primitive into a full kernel compromise without additional friction.
## Root Cause
Inside `ExpGetProcessInformation`, the SystemProcessInformationExtension (class 253) handler dispatches based on the caller-supplied `SystemInformationLength`. The intended invariant is that any non-NULL `SystemInformation` pointer must be validated with `ProbeForWrite(SystemInformation, Length, Alignment)` before any write occurs. The defective branch, however, is taken when `Length == 0`: the code skips ProbeForWrite (because the length is zero and the developer assumed no write would occur) but still performs an `InterlockedIncrement` (or equivalent atomic add) against a fixed offset inside the buffer to update an internal counter / version field. The increment is executed at `SystemInformation + offset` against the raw user pointer, which the kernel never validated. By choosing `SystemInformation` to point at any kernel virtual address, the attacker forces a 4-byte (DWORD) increment to that target.
The primitive is exceptionally clean: it is single-syscall, deterministic on every Windows build between Windows 11 24H2 RTM and 25H2 (prior to the May 2026 patch), requires no race window, no heap manipulation, no spray, no information leak prerequisite, and does not depend on any sensitive APIs that browser sandboxes block. The only constraints are (a) the write is an addition, not an arbitrary write, and (b) the offset is fixed by the SystemProcessInformationExtension layout.
## Exploitation Chain
1. **Initial Trigger.** The attacker (running in a low-privilege or sandboxed context such as a Chromium renderer) constructs a call: `NtQuerySystemInformation(0xFD /*SystemProcessInformationExtension*/, TargetKernelAddress, 0, &ReturnLength)` and obtains a +4-byte increment at `TargetKernelAddress + KnownOffset`.
2. **Bootstrapping Arbitrary Read via CmpLayerVersions.** Ori Nimron's chain corrupts the registry configuration manager's `CmpLayerVersions` table — a globally referenced kernel structure whose entries include length/pointer fields the kernel later treats as trustworthy when servicing registry layer queries. By incrementing the high bits of an entry's pointer field byte-by-byte, the attacker redirects subsequent reads through `NtQueryKey`-class APIs (or related registry hive APIs) to user-controlled memory, transforming the increment primitive into an arbitrary kernel read primitive.
3. **EPROCESS Walk & KASLR Defeat.** With arbitrary read, the attacker locates the kernel base, walks `PsActiveProcessHead` to enumerate the EPROCESS list, and identifies the System (PID 4) process and the attacker's own EPROCESS.
4. **Token Replacement / SYSTEM Privilege.** The increment primitive (now combined with the read) is used to either replace the attacker process's `Token` pointer with System's token, or to manipulate the token's `Privileges` and `IntegrityLevel` fields. The result is a SYSTEM-integrity, full-privilege process.
5. **Browser-Sandbox Reach.** Because `NtQuerySystemInformation` is not on the Win32k lockdown list, is not blocked by AppContainer / Restricted Token policies in default Chrome/Edge/Firefox sandbox profiles, and does not require an integrity check beyond the existing token, a compromised renderer can call it directly. This vulnerability therefore lifts the privilege ceiling of any RCE-in-renderer exploit from sandbox-confined to SYSTEM in a single syscall + kernel-read chain.
## Defensive Considerations
Detection should focus on (a) anomalous NtQuerySystemInformation invocations with SystemInformationClass=253 and SystemInformationLength=0 originating from browser renderer processes (chrome.exe, msedge.exe, firefox.exe child processes, or content/utility processes), (b) BSODs or memory-corruption symptoms following such calls on unpatched hosts, and (c) post-exploitation behaviors typical of token theft — sudden integrity-level uplift of a child renderer process, parent/child mismatches where a normally Low-integrity process spawns a SYSTEM-integrity child, and subsequent LSASS / registry hive access from previously sandboxed PIDs. EDR vendors that perform kernel-callback-based syscall monitoring (PsSetCreateProcessNotifyRoutine, ObRegisterCallbacks for token-pointer changes) can flag the token-swap stage even when the primitive itself is missed.
The definitive mitigation is the May 2026 cumulative update; no reliable runtime workaround exists short of disabling the affected browsers or running them under HVCI/VBS with the latest kernel patches applied. Windows Defender Application Guard, with its Hyper-V isolation, contains the post-exploitation blast radius but does not block the primitive itself.
MITRE ATT&CK techniques used in TL-2026-0604
Credential Access
T1003.001 OS Credential Dumping: LSASS Memory
Discovery
T1012 Query Registry; T1057 Process Discovery; T1082 System Information Discovery
Defense Evasion
T1055 Process Injection; T1134 Access Token Manipulation; T1211 Exploitation for Stealth
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1134.001 Access Token Manipulation: Token Impersonation/Theft; T1134.002 Access Token Manipulation: Create Process with Token; T1134.004 Access Token Manipulation: Parent PID Spoofing
Execution
T1106 Native API; T1203 Exploitation for Client Execution
Initial Access
Affected products and versions in Windows Kernel CVE-2026-40369
- Microsoft — Windows 11 24H2
Vulnerable versions: x64 < 10.0.26100.8390; arm64 < 10.0.26100.8390
Fixed in: 10.0.26100.8390 - Microsoft — Windows 11 25H2
Vulnerable versions: x64 < 10.0.26200.8390; arm64 < 10.0.26200.8390
Fixed in: 10.0.26200.8390 - Microsoft — Windows 11 26H1
Vulnerable versions: x64 < 10.0.28000.2113; arm64 < 10.0.28000.2113
Fixed in: 10.0.28000.2113 - Microsoft — Windows Server 2025
Vulnerable versions: < 10.0.26100.32772
Fixed in: 10.0.26100.32772
Remediation for Windows Kernel CVE-2026-40369
Patches
- Microsoft Security Update KB for CVE-2026-40369 — May 2026 Patch Tuesday (2026-05-12). Build floors: Windows 11 24H2 ≥ 10.0.26100.8390; Windows 11 25H2 ≥ 10.0.26200.8390; Windows 11 26H1 ≥ 10.0.28000.2113; Windows Server 2025 ≥ 10.0.26100.32772.
- Google Chrome stable channel update (post-2026-05-12) — incorporates renderer-side mitigations and warns telemetry on suspicious syscall patterns.
- Microsoft Edge stable channel update (post-2026-05-12).
- Mozilla Firefox ESR/Stable update (post-2026-05-12).
Immediate actions
- Deploy the May 2026 cumulative update across all Windows 11 24H2/25H2/26H1 and Windows Server 2025 endpoints (minimum builds: 24H2 10.0.26100.8390, 25H2 10.0.26200.8390, 26H1 10.0.28000.2113, Server 2025 10.0.26100.32772).
- Force all major browsers (Chrome, Edge, Firefox) to their latest stable channel and require restart after deployment to ensure sandbox brokers are running patched binaries.
- Enable Hypervisor-Protected Code Integrity (HVCI) and Virtualization-Based Security (VBS) on all eligible endpoints — does not block the primitive but raises post-exploitation cost (token theft becomes detectable via Credential Guard telemetry).
- In high-assurance environments, deploy Windows Defender Application Guard or browser-in-Hyper-V isolation modes to contain renderer compromise.
Workarounds
- No reliable in-product workaround exists — the affected syscall cannot be disabled without breaking core OS functionality (Task Manager, perf counters, EDR products).
- Compensating controls: enforce browser-in-isolation (WDAG / Sandboxie+ / Hyper-V VM browsing), restrict execution of unsigned binaries, and apply WDAC to limit attacker tooling staging.
- Detect-and-respond: deploy the Sigma/SPL/KQL rules below until patching is complete.
Longer-term hardening
- Adopt EDR products with kernel-callback-based token integrity monitoring (ObRegisterCallbacks on EPROCESS Token field changes) capable of detecting cross-process token swaps independent of the kernel primitive used.
- Standardize on Microsoft-signed browsers and enforce application allowlisting via Windows Defender Application Control (WDAC) to prevent untrusted browser builds from reaching the syscall.
- Implement EDR detections for anomalous NtQuerySystemInformation invocations from non-system, non-EDR processes (especially child renderer processes) and for sudden integrity-level uplifts on existing PIDs.
- Subscribe to MSRC and CISA KEV feeds and integrate same-day patch SLAs for kernel LPEs with browser-sandbox reachability.
CVEs associated with Windows Kernel CVE-2026-40369
Weaknesses (CWE) in Windows Kernel CVE-2026-40369
CWE-822
Timeline of Windows Kernel CVE-2026-40369
- Security researcher Ori Nimron identifies anomalous behavior in NtQuerySystemInformation class 253 during kernel fuzzing of SystemProcessInformationExtension code paths.
- Nimron isolates the ProbeForWrite bypass: ExpGetProcessInformation skips pointer validation when SystemInformationLength == 0, then performs an InterlockedIncrement against the user-supplied pointer — confirming arbitrary kernel memory increment primitive.
- Coordinated disclosure: Nimron submits the vulnerability and PoC chain (CmpLayerVersions corruption → arbitrary read → EPROCESS walk → token replacement) to the Microsoft Security Response Center (MSRC).
- MITRE/Microsoft assign CVE-2026-40369 and classify the weakness as CWE-822 (Untrusted Pointer Dereference).
- Microsoft releases fix in the May 2026 Patch Tuesday cumulative update for Windows 11 24H2 (10.0.26100.8390), 25H2 (10.0.26200.8390), 26H1 (10.0.28000.2113), and Server 2025 (10.0.26100.32772). NVD publishes the CVE with CVSS 7.8.
- NVD completes analysis: vulnerability marked as Analyzed with CVSS v3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H and impact 5.9, exploitability 1.8.
- Cyber Security News publishes Nimron's technical writeup, revealing browser-sandbox reachability and the full exploit chain — elevating community awareness and detection-rule development urgency.
- As of 2026-05-29, CVE-2026-40369 was patched by Microsoft on 2026-05-12 with no in-the-wild exploitation reported and no CISA KEV listing. It remains a live concern because Ori Nimron's full weaponized exploit is public on GitHub, Microsoft rated it "Exploitation More Likely," and unpatched Win11/Server 2025 hosts stay browser-sandbox-escape exploitable.
Sources cited for Windows Kernel CVE-2026-40369
- NVD — CVE-2026-40369
- Microsoft MSRC — CVE-2026-40369 Update Guide
- Cyber Security News — Windows Kernel Vulnerability Allows Attackers to Modify Kernel Memory Counters
- MITRE CWE-822 — Untrusted Pointer Dereference
- Microsoft Docs — NtQuerySystemInformation Routine
- Microsoft Docs — ProbeForWrite Kernel Routine
- MITRE ATT&CK — T1068 Exploitation for Privilege Escalation
- MITRE ATT&CK — T1134.001 Token Impersonation/Theft
Threats related to Windows Kernel CVE-2026-40369
Detection coverage for TL-2026-0604
As of 2026-05-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0604 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.