Windows Kernel Elevation of Privilege Vulnerability

MonitorCVSS 4.7CVE-2026-49167Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free vulnerability in the Windows kernel allows a user with local login access to execute code with kernel privileges, bypassing normal privilege boundaries. The flaw exists in Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2019, 2022, and 2025 across all architectures (32-bit, x64, ARM64). Microsoft has released patches for all affected versions.

What this means
What could happen
A user with local access to a Windows workstation or server could exploit a memory flaw in the kernel to gain administrative privileges, potentially allowing them to modify system configurations, install malware, or interfere with critical applications running on that machine.
Who's at risk
Any organization running Windows 10, Windows 11, Windows Server 2019, 2022, or 2025 on engineering workstations, HMI systems, data historians, or administrative servers is affected. This impacts control system networks where operators or engineers use Windows-based systems to interact with or manage industrial equipment.
How it could be exploited
An attacker with local login access runs a specially crafted application that exploits a use-after-free condition in the Windows kernel. The kernel flaw allows the application to allocate freed memory and execute code with system privileges, bypassing normal user-level restrictions.
Prerequisites
  • Local login access to the Windows system
  • User-level account (not administrative)
  • Ability to execute arbitrary applications
Requires local accessRequires low-level user accountLow attack complexityAffects system integrity and availabilityAffects all major Windows versions in active use
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (19)
19 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/10
Schedule — requires maintenance window
0/9

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9020 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5386 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33158 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit) to Build 10.0.17763.9020 or later
HOTFIXUpdate Windows 10 Version 1809 (x64) to Build 10.0.17763.9020 or later
HOTFIXUpdate Windows 10 Version 21H2 (all architectures) to Build 10.0.19044.7548 or later
HOTFIXUpdate Windows 10 Version 22H2 (all architectures) to Build 10.0.19045.7548 or later
HOTFIXUpdate Windows 11 Version 24H2 and 25H2 (all architectures) to Build 10.0.26100.8875 or later
HOTFIXUpdate Windows 11 Version 26H1 (all architectures) to Build 10.0.28000.2525 or later
Long-term hardening
0/1
HARDENINGRestrict local login access to Windows systems to trusted users only; disable unnecessary local accounts
API: /api/v1/advisories/96420bc5-d24c-49ed-b9fc-3e65c40bfe1f

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Kernel Elevation of Privilege Vulnerability | CVSS 4.7 - OTPulse