// 3 ZERO-DAY · 5 CVE · 4 EXPLOIT IN THE LAST 24H→
CVE-2026-50375 in the DirectX Graphics Kernel driver: Microsoft confirms patch and 'More Likely' exploitability, but CVSS scores diverge sharply between 6.3 and 8.8 depending on the source.

Microsoft released the patch for CVE-2026-50375 on October 1, 2026, a vulnerability in the Windows kernel's dxgkrnl.sys driver that allows local privilege escalation via a Time-Of-Check Time-Of-Use race condition. The flaw, cataloged as ZDI-26-751 by the TrendAI Zero Day Initiative, presents a rarity in the advisory landscape: the CVSS score varies significantly across sources, with ZDI assigning 8.8 while the CVE.org record and Microsoft settle on 6.3 MEDIUM.

Key Takeaways
  • The vulnerability resides in the dxgkrnl.sys driver (DirectX Graphics Kernel) and is caused by a lack of locking on shared object operations
  • A local attacker with low-privileged code execution can escalate to kernel and execute arbitrary code in that context
  • Microsoft rates severity as "Important" with an exploitability assessment of "More Likely"
  • The official CVE CVSS is 6.3 (MEDIUM) with vector AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H, while ZDI assigns 8.8 to the same flaw

The TOCTOU Mechanism at the Heart of the Graphics Kernel

The dxgkrnl.sys driver manages low-level operations for the DirectX graphics subsystem, interfacing directly with hardware and the Windows kernel. According to advisory ZDI-26-751, the vulnerability is a classic Time-Of-Check Time-Of-Use race condition:

"The specific flaw exists within the dxgkrnl.sys driver. The issue results from the lack of proper locking when performing operations on an object."
— TrendAI Zero Day Initiative, Advisory ZDI-26-751

The absence of proper synchronization allows a malicious thread to alter the state of a shared object between the moment of verification and the moment of actual use. This temporal disconnect generates a heap-based buffer overflow, confirmed by the CVE.org record, which turns the race condition into a concrete vehicle for escalation.

ZDI specifies that the attacker must already have the ability to execute low-privileged code on the target system. From this initial foothold, the exploitation chain leads to kernel privileges: "An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel." Execution in the kernel context implies total control over the operating system, with the ability to bypass any user-mode security mechanism.

Why the CVSS Splits: 8.8 vs 6.3

The scoring discrepancy between ZDI and the official CVE/Microsoft sources is not a typo but reflects divergent evaluation methodologies on the same technical basis. Both scores derive from the CVSS:3.1 vector AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H, which describes local access (AV:L), high attack complexity (AC:H), low privileges required (PR:L), no user interaction (UI:N), unchanged scope (S:U), no confidentiality impact (C:N), and high integrity/availability impact (I:H/A:H).

The CVE.org score of 6.3 MEDIUM incorporates environmental constraints: the attack requires race-window conditions that limit practicality. ZDI's 8.8 appears to weigh the final impact—arbitrary kernel execution—more heavily while retaining the same base vector. Microsoft, in its MSRC advisory, does not publish a numeric CVSS of its own but classifies severity as "Important," positioning itself conceptually closer to the CVE reading than to ZDI's.

For organizations, this divergence creates a prioritization problem: the 6.3 MEDIUM could push the patch to the back of the queue, while Microsoft's "More Likely" exploitability assessment and the kernel context suggest preferential treatment.

The Timeline: July to October With Coordinated Disclosure

The vulnerability was reported to Microsoft on July 3, 2026, by researchers Thanatos Tian (Hong Kong Polytechnic University), wgg, and npc0vo with Diffract, who shared the discovery with the TrendAI Zero Day Initiative. The three months of coordinated handling concluded with the public release of the advisory and patch on October 1, 2026.

Microsoft confirmed that "A complete vendor solution is available" and that exploit status is "No" for public code existence and "No" for confirmed in-the-wild exploitation. The "More Likely" exploitability assessment indicates, however, that based on available information, Microsoft considers the development of working exploits technically probable.

What to Do Now

Priority actions for Windows organizations:

  • Apply the Microsoft security update released as part of the October 2026 cycle, verifying the presence of CVE-2026-50375 in the installed bulletins catalog
  • Evaluate priority escalation for systems hosting users with unprivileged code execution capability—multi-user terminals, terminal servers, shared workstations—given the local vector and "More Likely" exploitability
  • Ensure internal vulnerability scanning engines correctly report the official 6.3 CVSS and do not over- or under-estimate risk based on misaligned aggregator scores
  • Monitor for the potential appearance of proof-of-concept code in public repositories, given that Microsoft currently confirms no public exploits but leaves the "More Likely" window open

Kernel Graphics Drivers as a Recurring Attack Surface

The flaw in dxgkrnl.sys fits a well-established pattern: graphics subsystem drivers represent one of the most fertile attack surfaces in the Windows kernel. The complexity of memory management operations, the need for real-time performance, and direct interaction with heterogeneous hardware create ideal conditions for race conditions and buffer overflows. The DirectX Graphics Kernel component in particular has hosted similar vulnerabilities in the past, confirming that the attack surface is not anomalous but systemic.

The TOCTOU nature of CVE-2026-50375 adds a detection challenge: the exploit does not necessarily leave obvious traces in user-mode logs, and the race condition can be triggered in millisecond windows. The lack of confidentiality impact (C:N in CVSS) does not mitigate the risk: an attacker who reaches the kernel can subsequently extract any data in memory, an operation the CVSS score does not capture because it follows the initial escalation.

The case of divergent scoring between ZDI and CVE.org offers a moment of reflection for the industry. Organizations that rely on CVSS thresholds for automated patch prioritization risk underestimating vulnerabilities with catastrophic impact but complex attack constraints. Microsoft's "More Likely" exploitability assessment, while not a numeric score, provides contextual information that CVSS alone does not convey.

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. zerodayinitiative.com
  2. cve.org
  3. msrc.microsoft.com
  4. trendmicro.com