Windows Kernel Information Disclosure Vulnerability

MonitorCVSS 5.5CVE-2026-50316Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Windows Kernel vulnerability (CVE-2026-50316) allows an authorized local user to read sensitive kernel information from log files. Affected versions include Windows Server 2022, 2025, Windows 10 (all 21H2 and 22H2 builds), and Windows 11 (24H2, 25H2, 26H1 builds). Microsoft has released patches for all versions. Exploitation is considered unlikely in practice.

What this means
What could happen
An attacker with local access to a Windows system could read sensitive kernel information from log files, potentially exposing configuration details or credentials that could be used in follow-up attacks. This risk is low for most OT environments but elevated if engineering workstations or HMI servers run Windows and are accessible to untrusted users.
Who's at risk
Windows Server administrators and operators of HMI/engineering workstations running Windows 10, Windows 11, or Windows Server 2022/2025 should apply this update. The risk is highest for systems where multiple users have local access or where service accounts may be compromised.
How it could be exploited
An attacker with a local user account on the Windows system can access log files where the kernel has written sensitive information. No network access is required. The attacker reads the exposed data directly from the filesystem to gain information about the system or network.
Prerequisites
  • Local user account on the Windows system
  • Access to log files or directories where kernel information is written
Local access only (not remotely exploitable)Requires valid local user credentialsAffects confidentiality of kernel information
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (15)
15 with fix
ProductAffected VersionsFix Status
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows 10 Version 21H2 for 32-bit SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 21H2 for ARM64-based SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 21H2 for x64-based SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 22H2 for x64-based SystemsAll versionsBuild 10.0.19045.7548
Windows 10 Version 22H2 for ARM64-based SystemsAll versionsBuild 10.0.19045.7548
Windows 10 Version 22H2 for 32-bit SystemsAll versionsBuild 10.0.19045.7548
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply Microsoft July 2026 security update (or later) to all Windows systems
Long-term hardening
0/2
HARDENINGRestrict local user account creation and access to non-essential Windows systems; use principle of least privilege
HARDENINGReview and restrict file system permissions on log directories to prevent unauthorized read access
API: /api/v1/advisories/31efc1a4-d1af-42a3-a113-34896acf5664

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.