Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-50325Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A vulnerability in Windows Win32k kernel driver allows improper access control, permitting a user with a local account to elevate their privileges to administrator level. This affects Windows 10 (versions 1607, 1809, 21H2, and 22H2 on 32-bit, x64, and ARM64 architectures), Windows 11 (versions 24H2, 25H2, and 26H1), Windows Server 2016, 2019, 2022, and 2025. Microsoft has released fixes for all affected versions.

What this means
What could happen
A user with local access to a Windows workstation or server could run commands with elevated (administrator) privileges, potentially allowing them to modify process control logic, disable security software, or alter system configurations that affect plant operations.
Who's at risk
This affects organizations running Windows workstations or servers in industrial control environments, particularly engineering workstations, HMI (human-machine interface) hosts, and data servers running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025. Water utilities, electric utilities, and manufacturers using Windows-based SCADA or control software are at risk.
How it could be exploited
An attacker with a user account on a Windows machine (such as an engineering workstation or HMI host) could exploit improper access control in the Win32k kernel driver to escalate their privileges to administrator level. Once elevated, they could modify or stop industrial control applications running on that machine.
Prerequisites
  • Local user account on the Windows system
  • Ability to execute code as a standard user (not administrator)
  • Physical access to or RDP access to the machine
Privilege escalationLocal user requiredMedium complexityAffects control system workstationsActively exploited vulnerability (more likely)
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/4
Do now
0/2
HARDENINGRestrict local access to engineering workstations and HMI servers to authorized personnel only; disable unnecessary local accounts
WORKAROUNDDisable or restrict Remote Desktop Protocol (RDP) access to industrial control systems unless explicitly required for remote operations
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the July 2026 Windows security update to all affected systems (see product_fixes for specific build numbers by Windows version)
Long-term hardening
0/1
HARDENINGImplement application whitelisting on control system workstations to prevent unauthorized code execution
API: /api/v1/advisories/d9e10dc9-f6c5-4a62-aa87-90100661d700

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.