Win32k Elevation of Privilege Vulnerability
Plan PatchCVSS 7CVE-2026-50297Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
A flaw in Windows Win32k kernel component allows improper access control, enabling an authorized local user to escalate privileges to SYSTEM level. This affects Windows 10 (all recent versions), Windows 11 (all versions), Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures.
What this means
What could happen
A user with a local account on a Windows system could exploit this flaw to run commands with elevated (administrative) privileges, potentially compromising the entire computer and any operational systems running on it.
Who's at risk
Any organization running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 systems. This includes corporate workstations, engineering stations, HMI (human-machine interface) computers, and any historian or gateway servers running Windows. Critical for water/electric utilities where Windows servers manage SCADA networks, remote terminal units (RTUs), or data collection systems.
How it could be exploited
An attacker with a user account on the Windows system would exploit an access control flaw in the Win32k kernel component to escalate their privileges to SYSTEM/administrator level. This does not require network access—only local access to the computer.
Prerequisites
- Valid user account on the Windows system (local login or Remote Desktop access)
- Low complexity attack - no special tools required
Requires local account accessLow complexity attackAffects multiple Windows versions and architecturesElevation of privilege could allow full system compromise
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply Microsoft's July 2026 security update for your Windows version (see product fixes for specific build numbers)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/f6201886-6bdd-4d8a-a1cf-b6af148a3034Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.