Windows Kernel Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-49808Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A race condition in the Windows Kernel allows a user with valid local account credentials to elevate privileges to system level. The vulnerability exists in concurrent resource access with improper synchronization. This affects Windows Server 2025 and Windows 11 (versions 24H2, 25H2, and 26H1) on both x64 and ARM64 architectures. Exploitation is assessed as less likely and requires local code execution by an already-authenticated user.

What this means
What could happen
A local user with valid credentials on a Windows workstation or server could exploit a race condition to gain system-level privileges, potentially allowing them to modify critical infrastructure software or access sensitive configuration data.
Who's at risk
This affects operators and IT staff managing Windows Server 2025 and Windows 11 systems (versions 24H2, 25H2, and 26H1). Any industrial or utility organization running modern Windows infrastructure for engineering workstations, data analysis, or supervisory systems should apply this update to prevent unauthorized privilege escalation by authorized users who could compromise software integrity or access restricted configurations.
How it could be exploited
An attacker with a standard user account on a Windows system exploits a race condition in the kernel to escalate privileges to system level. This requires local access and the ability to run code on the machine, but no special complexity or user interaction.
Prerequisites
  • Valid user account on the Windows system
  • Ability to execute code locally on the affected system
  • Access to a shared resource being accessed by kernel processes
Requires valid user account on the systemLocal execution only, not remotely exploitableLow EPSS score (0.1%)Race condition—requires specific timing
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.8875
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.8875
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.8875
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.8875
Windows Server 2025All versionsBuild 10.0.26100.33158
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2269
Windows 11 Version 26H1 for ARM64-based SystemsAll versionsBuild 10.0.28000.2525
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2025
HOTFIXInstall Microsoft 2026-Jul security update on all Windows Server 2025, Windows 11 24H2, 25H2, and 26H1 systems
API: /api/v1/advisories/45001e05-8002-40f1-87eb-d7405b6e7be9

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Kernel Elevation of Privilege Vulnerability | CVSS 7.8 - OTPulse