The Zero Day Initiative has published ZDI-26-751, disclosing CVE-2026-50375 — a Time-of-Check Time-of-Use (TOCTOU) race condition in the Microsoft Windows DirectX graphics kernel subsystem (dxgkrnl.sys) that allows a local attacker to escalate privileges, rated CVSS 8.8 (High). This is not a theoretical concern for enterprise defenders: kernel-mode LPEs in dxgkrnl are a recurring, proven exploitation primitive. Threat actors consistently chain bugs exactly like this one after initial access — phishing payload lands as a standard user, and the kernel LPE converts that foothold into NT AUTHORITY\SYSTEM in seconds.
The exploitation prerequisite matters for triage but should not breed complacency: an attacker must first execute low-privileged code on the host. In modern intrusion chains — ransomware affiliates, initial access brokers, APT intrusion sets — that prerequisite is already satisfied by the time an LPE is invoked. If you run Windows endpoints, this advisory applies to you. Treat it as a priority patch candidate and assume it will be weaponized into post-exploitation toolkits quickly, if it hasn't been already.
Technical Analysis
Affected Component
The flaw resides in dxgkrnl.sys, the DirectX Graphics Kernel driver — the core kernel-mode component that brokers GPU scheduling, memory allocation, and device context management for every Windows system with a display stack. Because virtually every Windows workstation and server maintains this driver in the kernel, the attack surface is effectively universal across supported Windows desktop and server builds. Refer to the ZDI advisory and the corresponding Microsoft security update guide entry for the definitive list of affected builds for your environment.
How the Vulnerability Works
A TOCTOU race condition occurs when the kernel validates a condition (the check) and then acts on a resource (the use), with an attacker-controlled window in between where the resource's state can be swapped. In graphics kernel drivers, this class of bug typically manifests when user-mode-controllable objects — shared memory sections, device contexts, or object handles passed through the DDI (device driver interface) — are validated once and then dereferenced again without proper locking or re-validation. By winning the race, the attacker causes the kernel to operate on a substituted or corrupted object, yielding a kernel-memory read/write primitive or a direct privilege transition.
The exploitation chain from a defender's perspective:
- Initial access: Attacker executes code as a low-integrity / standard-user process (phishing, malicious document, compromised service account).
- Race triggering: The exploit makes repeated, precisely timed calls into the graphics stack (DirectX/GDI surface operations) to hit the TOCTOU window in
dxgkrnl.sys. - Privilege transition: A successful race yields token manipulation or kernel memory corruption, flipping the process token to SYSTEM or spawning a SYSTEM-integrity child process.
- Post-exploitation: Credential dumping, EDR tampering, persistence, and lateral movement follow immediately.
The observable fingerprint that defenders can reliably catch is step 3→4: the abrupt integrity-level transition where a user-context process (browser, Office app, script host, or injected payload) produces SYSTEM-integrity children. Race-condition exploits also tend to be noisy at the syscall level — high-frequency, repetitive device interactions — and failed attempts may produce kernel bugchecks or dxgkrnl-related crash events, which are themselves a tripwire.
Exploitation Status
At the time of writing, ZDI has published the advisory with coordinated-disclosure detail limited to the vulnerability class and impact. There is no confirmed public in-the-wild exploitation or CISA KEV listing for CVE-2026-50375 as of this publication — but given the 8.8 rating, the kernel attack surface, and the historical cadence of dxgkrnl LPE weaponization, defenders should operate on an assume-breach timeline. Monitor CISA KEV and vendor channels for escalation of status.
Detection & Response
Post-exploitation behavior is your highest-fidelity detection surface for an LPE like this. The two rules below target the integrity-level transition and the filesystem-redirection tradecraft commonly paired with TOCTOU exploitation, with scoping chosen to keep false-positive rates survivable in a real SOC.
---
title: Low-Integrity User Process Spawning SYSTEM-Integrity Child
description: Detects the hallmark of local privilege escalation exploitation (e.g., CVE-2026-50375 dxgkrnl TOCTOU) where a browser, Office application, or script host running in a user context spawns a child process at SYSTEM integrity. Legitimate software updaters are filtered to reduce noise.
references:
- http://www.zerodayinitiative.com/advisories/ZDI-26-751/
- https://attack.mitre.org/techniques/T1068/
author: Security Arsenal
date: 2026/04/06
status: experimental
tags:
- attack.privilege_escalation
- attack.t1068
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\chrome.exe'
- '\msedge.exe'
- '\firefox.exe'
- '\winword.exe'
- '\excel.exe'
- '\powerpnt.exe'
- '\outlook.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\rundll32.exe'
selection_integrity:
IntegrityLevel: 'System'
filter_updaters:
Image|endswith:
- '\GoogleUpdate.exe'
- '\MicrosoftEdgeUpdate.exe'
- '\setup.exe'
CommandLine|contains:
- 'MicrosoftEdgeUpdate'
- 'GoogleUpdate'
condition: selection_parent and selection_integrity and not filter_updaters
falsepositives:
- Enterprise software deployment agents triggered from user sessions
- Rare browser component installers (filtered above)
level: high
---
title: Non-Admin Junction or Symlink Creation Indicative of TOCTOU Redirection
description: Detects creation of NTFS junctions or symbolic links from command-line tooling, a technique frequently used to weaponize race-condition vulnerabilities by redirecting privileged file operations during the check/use window.
references:
- http://www.zerodayinitiative.com/advisories/ZDI-26-751/
- https://attack.mitre.org/techniques/T1068/
author: Security Arsenal
date: 2026/04/06
status: experimental
tags:
- attack.privilege_escalation
- attack.t1068
logsource:
category: process_creation
product: windows
detection:
selection_cmd:
Image|endswith: '\cmd.exe'
CommandLine|contains:
- 'mklink /J'
- 'mklink /D'
- 'mklink /H'
selection_ps:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
CommandLine|contains:
- 'New-Item'
- 'SymbolicLink'
- 'Junction'
condition: selection_cmd or selection_ps
falsepositives:
- Developer workflows and software packaging scripts
- IT provisioning scripts that create profile redirection links
level: medium
// Hunt: integrity-level transition consistent with local privilege escalation (CVE-2026-50375 / dxgkrnl TOCTOU)
// Looks for SYSTEM-integrity processes whose initiating process was running at Low/Medium integrity from a user-context binary.
DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where ProcessIntegrityLevel in~ ("System", "High")
| where InitiatingProcessIntegrityLevel in~ ("Low", "Medium")
| where InitiatingProcessFileName in~ (
"chrome.exe", "msedge.exe", "firefox.exe", "winword.exe", "excel.exe",
"powerpnt.exe", "outlook.exe", "wscript.exe", "cscript.exe", "mshta.exe",
"rundll32.exe", "powershell.exe", "cmd.exe")
| where FileName !in~ ("GoogleUpdate.exe", "MicrosoftEdgeUpdate.exe", "setup.exe", "msiexec.exe")
| summarize ProcessCount = count(),
Commands = make_set(ProcessCommandLine, 5),
Devices = make_set(DeviceName, 10)
by InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, AccountName, bin(TimeGenerated, 1h)
| order by TimeGenerated desc;
// Secondary hunt: high-frequency graphics-stack interaction bursts from a single user process,
// a possible signature of race-condition trigger loops hammering dxgkrnl via GDI/DirectX calls.
// Tune the threshold to your baseline; start at 500 events/minute per process.
DeviceEvents
| where TimeGenerated > ago(24h)
| where ActionType contains "Device" or InitiatingProcessCommandLine has_any ("gdi32", "d3d", "dxgi")
| summarize EventVolume = count() by DeviceName, InitiatingProcessFileName, InitiatingProcessId, bin(TimeGenerated, 1m)
| where EventVolume > 500
| order by EventVolume desc;
-- Hunt for SYSTEM-level processes whose parent is a user-context application,
-- the post-exploitation fingerprint of a successful dxgkrnl LPE (CVE-2026-50375).
LET user_procs = SELECT Pid, Name, Exe, Username
FROM pslist()
WHERE Name =~ '(?i)(chrome|msedge|firefox|winword|excel|powerpnt|outlook|wscript|cscript|mshta|rundll32|powershell|cmd)\.exe$'
AND Username !~ '(?i)(SYSTEM|LOCAL SERVICE|NETWORK SERVICE)'
SELECT P.Pid AS SystemPid,
P.Name AS SystemProcess,
P.Exe AS SystemExe,
P.Username AS SystemUser,
P.CreateTime AS SpawnTime,
U.Name AS ParentName,
U.Username AS ParentUser,
U.Exe AS ParentExe
FROM pslist() AS P
JOIN user_procs AS U ON P.Ppid = U.Pid
WHERE P.Username =~ '(?i)SYSTEM'
AND P.Name !~ '(?i)(googleupdate|microsoftedgeupdate|setup|msiexec)\.exe$'
# CVE-2026-50375 (ZDI-26-751) — dxgkrnl TOCTOU LPE verification and remediation script
# Run elevated. Validates driver version, patch posture, and triggers an update scan.
# 1. Capture current dxgkrnl.sys version for comparison against the Microsoft advisory
$driverPath = "$env:SystemRoot\System32\drivers\dxgkrnl.sys"
if (Test-Path $driverPath) {
$ver = (Get-Item $driverPath).VersionInfo
Write-Host "[INFO] dxgkrnl.sys version: $($ver.FileVersion) | ProductVersion: $($ver.ProductVersion)"
} else {
Write-Warning "dxgkrnl.sys not found at expected path — verify manually."
}
# 2. Report OS build to map against Microsoft's affected-products table
$os = Get-CimInstance Win32_OperatingSystem
Write-Host "[INFO] OS: $($os.Caption) | Build: $($os.BuildNumber).$((Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion').UBR)"
# 3. List security updates installed in the last 45 days — confirm the CVE-2026-50375 fix is present
Write-Host "[INFO] Recently installed hotfixes:"
Get-HotFix | Where-Object { $_.InstalledOn -gt (Get-Date).AddDays(-45) } |
Sort-Object InstalledOn -Descending | Format-Table HotFixID, Description, InstalledOn -AutoSize
# 4. Check for pending updates and force a Windows Update scan
$pending = (New-Object -ComObject Microsoft.Update.Session).CreateUpdateSearcher()
try {
$result = $pending.Search("IsInstalled=0 and Type='Software'")
Write-Host "[INFO] Pending updates found: $($result.Updates.Count)"
foreach ($u in $result.Updates) { Write-Host " - $($u.Title)" }
} catch {
Write-Warning "Update search failed: $_ — check WSUS/Intune compliance reporting instead."
}
# 5. Quick tripwire: enumerate suspicious junctions/symlinks in user-writable temp paths
Write-Host "[INFO] Scanning user temp directories for recently created reparse points..."
Get-ChildItem "$env:SystemDrive\Users" -Directory -ErrorAction SilentlyContinue | ForEach-Object {
Get-ChildItem "$($_.FullName)\AppData\Local\Temp" -Force -ErrorAction SilentlyContinue |
Where-Object { $_.Attributes -match 'ReparsePoint' -and $_.CreationTime -gt (Get-Date).AddDays(-7) } |
Select-Object FullName, CreationTime
}
# 6. Confirm LSA protection and Credential Guard posture to limit post-LPE damage
$credGuard = Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard -ErrorAction SilentlyContinue
if ($credGuard) {
Write-Host "[INFO] Credential Guard running: $($credGuard.SecurityServicesRunning -contains 1)"
}
$lsaRunAsPPL = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Lsa' -Name RunAsPPL -ErrorAction SilentlyContinue).RunAsPPL
Write-Host "[INFO] LSA RunAsPPL: $lsaRunAsPPL (1 = enabled)"
Remediation
- Patch immediately. Apply the Microsoft security update that resolves CVE-2026-50375 across all supported Windows client and server builds. Pull the authoritative affected-products matrix and KB identifiers from the Microsoft Security Update Guide entry for CVE-2026-50375 and the ZDI-26-751 advisory. Given the CVSS 8.8 kernel impact, fast-track this through your emergency change window rather than the standard monthly cycle — especially on multi-user systems, VDI farms, jump boxes, and any host where untrusted code execution is plausible.
- Prioritize by exposure. Rank remediation by systems where the prerequisite (low-privileged code execution) is most likely already met: user endpoints, terminal servers/RDSH, developer workstations, and internet-facing servers with local service accounts.
- Verify, don't assume. Use the script above (or your RCM/Intune compliance baselines) to confirm the updated
dxgkrnl.sysversion is actually deployed. Patch deployment failures on a subset of endpoints are the norm, not the exception. - No vendor workaround is published for a kernel race condition of this type — there is no registry key or feature toggle that safely neutralizes a TOCTOU in the graphics kernel. Defense-in-depth is your interim control: enforce WDAC/AppLocker policies to block unsigned and LOLBin-abusing executables in user contexts, restrict local admin rights aggressively, and keep Credential Guard and LSA Protection enabled so a successful SYSTEM transition yields less credential material.
- Hunt retroactively. Run the KQL and VQL queries above across at least the last 30 days of telemetry. An LPE deployed before patching leaves exactly the integrity-transition artifacts these queries target.
- Monitor CISA KEV. If CVE-2026-50375 is added to the Known Exploited Vulnerabilities catalog, federal-binding deadlines (typically 21 days for BOD 22-01 scoped agencies) and your own SLA should compress accordingly. Watch for proof-of-concept publication, which historically precedes rapid commodity-toolkit adoption of
dxgkrnlLPEs.
Conclusion
CVE-2026-50375 is the kind of vulnerability that rarely makes headlines but routinely decides intrusion outcomes. The initial-access phase of an attack gets the attention; the privilege-escalation phase is where containment is won or lost. A CVSS 8.8 TOCTOU in the Windows graphics kernel, reachable by any code running as a standard user, belongs at the top of this week's patch queue — and the integrity-transition detections above belong in your SIEM today, regardless of patch status.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.