Windows Kernel Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-50332Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Heap-based buffer overflow in Windows Kernel allows a local user to escalate privileges to system or administrator level. An attacker with an existing user account can trigger the overflow through a malicious program, gaining full control of the system without user interaction. Affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025.
What this means
What could happen
An attacker with local access to a Windows system could escalate their privileges to administrator or system level, allowing them to take complete control of the device and any connected networks or industrial equipment it manages.
Who's at risk
Organizations running Windows 10 (all recent versions: 1607, 1809, 21H2, 22H2), Windows 11 (all versions: 24H2, 25H2, 26H1), Windows Server (2016, 2019, 2022, 2025) should prioritize this patch. OT environments using Windows-based human-machine interfaces (HMIs), engineering workstations, or process historians are most at risk if those systems can be accessed by untrusted users or connected to external networks.
How it could be exploited
An attacker with an existing local user account on a Windows system would execute a malicious program that triggers a heap buffer overflow in the kernel, allowing them to escalate privileges without requiring administrator rights or user interaction. This could be delivered via email, USB, or compromised software.
Prerequisites
- Local user account on the Windows system
- Ability to execute code on the system (e.g., via email attachment, USB drive, or compromised application)
local privilege escalationlow complexity attackaffects OT workstations and HMIsactively being exploited (more likely per advisory)
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict local console and remote desktop access to engineering and operations staff only; disable remote desktop on HMI or workstations not requiring it
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXApply Microsoft's July 2026 security update (or later) to all Windows 10 and Windows Server systems. For specific versions: Windows 10 v1809 to Build 10.0.17763.9020, Windows 10 v21H2 to Build 10.0.19044.7548, Windows 10 v22H2 to Build 10.0.19045.7548, Windows 11 v24H2 to Build 10.0.26100.8875, Windows 11 v25H2 to Build 10.0.26200.8875, Windows Server 2016 to Build 10.0.14393.9339, Windows Server 2019 to Build 10.0.17763.9020, Windows Server 2022 to Build 10.0.20348.5386, Windows Server 2025 to Build 10.0.26100.33158
Long-term hardening
0/1HARDENINGImplement application whitelisting on engineering workstations and HMIs to prevent execution of unauthorized binaries
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/219dc67b-dad9-4c86-9333-c251c81f4631Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.