Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-50297Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A flaw in Windows Win32k kernel component allows improper access control, enabling an authorized local user to escalate privileges to SYSTEM level. This affects Windows 10 (all recent versions), Windows 11 (all versions), Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures.

What this means
What could happen
A user with a local account on a Windows system could exploit this flaw to run commands with elevated (administrative) privileges, potentially compromising the entire computer and any operational systems running on it.
Who's at risk
Any organization running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 systems. This includes corporate workstations, engineering stations, HMI (human-machine interface) computers, and any historian or gateway servers running Windows. Critical for water/electric utilities where Windows servers manage SCADA networks, remote terminal units (RTUs), or data collection systems.
How it could be exploited
An attacker with a user account on the Windows system would exploit an access control flaw in the Win32k kernel component to escalate their privileges to SYSTEM/administrator level. This does not require network access—only local access to the computer.
Prerequisites
  • Valid user account on the Windows system (local login or Remote Desktop access)
  • Low complexity attack - no special tools required
Requires local account accessLow complexity attackAffects multiple Windows versions and architecturesElevation of privilege could allow full system compromise
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply Microsoft's July 2026 security update for your Windows version (see product fixes for specific build numbers)
API: /api/v1/advisories/f6201886-6bdd-4d8a-a1cf-b6af148a3034

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Win32k Elevation of Privilege Vulnerability | CVSS 7 - OTPulse