Windows TCP/IP Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-50307Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free vulnerability in the Windows TCP/IP driver allows an authorized local user to elevate their privileges to administrator level. This affects Windows 10 (versions 1809, 21H2, and 22H2), Windows 11 (versions 24H2, 25H2, and 26H1), Windows Server 2019, 2022, and 2025 across all architectures. Microsoft has released patches for all affected versions. The vulnerability requires the attacker to already have local system access or the ability to execute code locally.

What this means
What could happen
A user with local login access could exploit a flaw in Windows TCP/IP to gain system administrator privileges, potentially allowing them to alter network configurations, disable security controls, or access sensitive data on the system.
Who's at risk
Windows IT administrators managing Windows 10, Windows 11, Windows Server 2019, Windows Server 2022, or Windows Server 2025 systems. This affects both standard workstations and server deployments across 32-bit, 64-bit, and ARM64 architectures. Any organization running these Windows versions should prioritize patching to prevent local privilege escalation.
How it could be exploited
An attacker with a local user account on the Windows system would exploit a use-after-free flaw in the TCP/IP driver to run code with administrator privileges. This requires the attacker to already have the ability to log in locally or execute code as a standard user on the target machine.
Prerequisites
  • Local user account or code execution capability on the Windows system
  • Ability to interact with TCP/IP stack
  • Windows system must be running one of the affected OS versions
Local privilege escalationLow complexity attackRequires low-level user privileges to exploit
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (19)
19 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2022
HOTFIXApply Microsoft's July 2026 security update to your Windows systems (Windows 10 Build 10.0.19045.7548, Windows 11 Build 10.0.26100.8875, or Windows Server 2022 Build 10.0.20348.5386 depending on your version)
API: /api/v1/advisories/f24a2732-8361-4f78-b216-94fa0bc58bfb

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows TCP/IP Elevation of Privilege Vulnerability | CVSS 7 - OTPulse