Windows Kernel Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-42984Jun 9, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free vulnerability in the Windows kernel allows an authorized local user to escalate privileges to SYSTEM level. The flaw affects Windows 10, Windows 11, Windows Server 2019, 2022, and 2025 across all supported versions and architectures. Microsoft has released patches in the June 2026 security update; exploitation is considered unlikely if patches are applied promptly.

What this means
What could happen
A user with local access to a Windows system could exploit a memory flaw in the kernel to gain system-level privileges, potentially allowing them to modify industrial application settings or access sensitive control system data. This risk is most relevant if your SCADA or HMI servers run Windows.
Who's at risk
Any organization running Windows 10, Windows 11, Windows Server 2019, or Windows Server 2022/2025 for engineering workstations, HMI servers, data historians, or other supervisory systems in your control environment. This particularly affects utilities and manufacturers using Windows-based SCADA platforms like GE FactoryTalk, Wonderware, or custom control applications.
How it could be exploited
An attacker with a local user account on a Windows system triggers a use-after-free condition in the kernel through a specially crafted request. Successful exploitation grants the attacker SYSTEM-level privileges, allowing them to modify kernel structures and take full control of the host, including any industrial applications running on it.
Prerequisites
  • Local user account on the affected Windows system
  • Ability to execute code or interact with the kernel (no remote exploitation path)
  • High complexity exploitation required (AC:H in CVSS)
Requires local access (not remotely exploitable)Requires valid user credentialsHigh complexity exploitationAffects all Windows versions broadly
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (22)
22 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.8880
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.8880
Windows Server 2019All versionsBuild 10.0.17763.8880
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.8880
Windows Server 2022All versionsBuild 10.0.20348.5256
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the June 2026 Windows security update to bring your systems to the patched build versions (e.g., Build 10.0.19045.7417 for Windows 10 22H2, Build 10.0.22631.7219 for Windows 11 23H2)
Long-term hardening
0/2
HARDENINGIf your SCADA/HMI application runs on Windows, verify it is running in a dedicated, air-gapped network segment to limit the impact if a local user gains elevated privileges
HARDENINGRestrict local user access to any Windows system running industrial control applications to only authorized personnel with a legitimate need
API: /api/v1/advisories/22b39c17-77e6-4971-9e97-67c5b1f8901c

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.