Windows TCP/IP Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-50306Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A use-after-free vulnerability in Windows TCP/IP stack allows a local attacker with user-level privileges to escalate to SYSTEM level. The vulnerability exists across Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 on 32-bit, x64, and ARM64 systems.
What this means
What could happen
A user with local access to a Windows system could escalate their privileges to SYSTEM level through a TCP/IP vulnerability, potentially allowing them to modify control system configurations, install malware, or disrupt operations on that machine.
Who's at risk
This affects all versions of Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 running on 32-bit, x64, and ARM64 architectures. Any facility using these Windows versions on workstations, engineering stations, HMI servers, or data historians should prioritize patching to prevent unauthorized privilege escalation by local users.
How it could be exploited
An attacker with a local user account on the Windows system can trigger a use-after-free condition in the TCP/IP driver to gain elevated privileges. This requires local code execution capability but does not require administrator rights to begin exploitation.
Prerequisites
- Local user account on the affected Windows system
- Ability to execute code on the system
Requires local accessLow complexity exploitationAffects all supported Windows versions
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the July 2026 Windows security update to all affected systems
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/52ac258f-9fb6-4521-9409-7323543165a4Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.