Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-49805Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

Improper access control in Windows Win32K allows an authorized local user to elevate privileges. An attacker with a local user account (non-administrator) can exploit this vulnerability to run commands with system-level privileges. This affects Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2016, 2019, 2022, and 2025. Microsoft has released fixes for all affected versions.

What this means
What could happen
An attacker with a local user account on a Windows workstation or server could exploit this vulnerability to run commands with system-level privileges, potentially allowing them to modify critical configurations, disable security controls, or compromise the integrity of the system.
Who's at risk
Organizations running Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, or 2025 are affected. This impacts any department or workstation where standard (non-administrator) user accounts exist, including engineering workstations, office PCs, historian servers, or any server with local user access.
How it could be exploited
An attacker with a local user account (non-administrator) executes a specially crafted command or application that exploits improper access control in the Windows Win32k subsystem to escalate privileges to system level. This requires the attacker to already have interactive access to the machine (e.g., a compromised standard user account, remote desktop session, or service account).
Prerequisites
  • Local user account on the affected Windows system
  • No administrative rights required
  • Interactive access to the system (local login or remote session)
Local privilege escalationRequires existing local account accessAffects all modern Windows versionsModerate EPSS score (2.1%)Exploitation more likely
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Jul security update to all affected Windows systems
Long-term hardening
0/2
HARDENINGRestrict interactive logon and remote desktop access to authorized personnel only
HARDENINGImplement application whitelisting or endpoint detection and response (EDR) to monitor for unusual privilege escalation attempts
API: /api/v1/advisories/dc45d405-7699-4718-b2a3-81dbf3fa6d77

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.