Windows Kernel Elevation of Privilege Vulnerability

Plan PatchCVSS 8.8CVE-2026-49795Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A use-after-free vulnerability in the Windows Kernel allows an authorized local attacker to elevate privileges. The vulnerability requires that the attacker already have an account on the system and be able to execute code locally.

What this means
What could happen
An attacker with a low-privilege account on your Windows server or workstation could gain administrative access, potentially allowing them to modify system settings, install persistent malware, or access sensitive data across the entire machine.
Who's at risk
Windows administrators responsible for Windows 10, Windows 11, Windows Server 2019, Windows Server 2022, and Windows Server 2025 systems. This affects all Windows deployments regardless of industry sector—municipal utilities, water authorities, hospitals, and manufacturing facilities using Windows for HMI, engineering workstations, or server infrastructure are all at risk.
How it could be exploited
An attacker would need an existing local user account on a Windows system. They would execute a specially crafted program that triggers the use-after-free condition in the Windows Kernel, escalating their privileges to administrator level without requiring additional credentials or user interaction.
Prerequisites
  • Local user account on the target Windows system
  • Ability to execute code (low-privilege user rights sufficient)
  • No additional user interaction required
Low complexity to exploitHigh severity (CVSS 8.8)Affects all supported Windows versionsLocal privilege escalationExploitation likely per Microsoft
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (19)
19 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/4
Do now
0/3
HOTFIXApply the July 2026 Microsoft security updates immediately to all Windows systems: Build 10.0.17763.9020 for Server 2019, Build 10.0.20348.5386 for Server 2022, Build 10.0.26100.33158 for Server 2025, Build 10.0.19044.7548 for Win10 21H2, Build 10.0.19045.7548 for Win10 22H2, Build 10.0.26100.8875 for Win11 24H2, Build 10.0.26200.8875 for Win11 25H2, Build 10.0.28000.2269 or later for Win11 26H1
HARDENINGRestrict local logon rights on critical Windows servers and HMI systems to authorized personnel only using Group Policy (Deny log on locally, Deny access to this computer from the network)
HARDENINGEnforce multi-factor authentication for all remote access to Windows systems to limit attack surface from compromised local accounts
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HARDENINGDisable unnecessary user accounts and remove local admin rights from standard users and engineers wherever possible
API: /api/v1/advisories/b0db8870-d032-4a41-b01f-421e0408e15b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.