Windows Kernel Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-50332Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Heap-based buffer overflow in Windows Kernel allows a local user to escalate privileges to system or administrator level. An attacker with an existing user account can trigger the overflow through a malicious program, gaining full control of the system without user interaction. Affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025.

What this means
What could happen
An attacker with local access to a Windows system could escalate their privileges to administrator or system level, allowing them to take complete control of the device and any connected networks or industrial equipment it manages.
Who's at risk
Organizations running Windows 10 (all recent versions: 1607, 1809, 21H2, 22H2), Windows 11 (all versions: 24H2, 25H2, 26H1), Windows Server (2016, 2019, 2022, 2025) should prioritize this patch. OT environments using Windows-based human-machine interfaces (HMIs), engineering workstations, or process historians are most at risk if those systems can be accessed by untrusted users or connected to external networks.
How it could be exploited
An attacker with an existing local user account on a Windows system would execute a malicious program that triggers a heap buffer overflow in the kernel, allowing them to escalate privileges without requiring administrator rights or user interaction. This could be delivered via email, USB, or compromised software.
Prerequisites
  • Local user account on the Windows system
  • Ability to execute code on the system (e.g., via email attachment, USB drive, or compromised application)
local privilege escalationlow complexity attackaffects OT workstations and HMIsactively being exploited (more likely per advisory)
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict local console and remote desktop access to engineering and operations staff only; disable remote desktop on HMI or workstations not requiring it
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXApply Microsoft's July 2026 security update (or later) to all Windows 10 and Windows Server systems. For specific versions: Windows 10 v1809 to Build 10.0.17763.9020, Windows 10 v21H2 to Build 10.0.19044.7548, Windows 10 v22H2 to Build 10.0.19045.7548, Windows 11 v24H2 to Build 10.0.26100.8875, Windows 11 v25H2 to Build 10.0.26200.8875, Windows Server 2016 to Build 10.0.14393.9339, Windows Server 2019 to Build 10.0.17763.9020, Windows Server 2022 to Build 10.0.20348.5386, Windows Server 2025 to Build 10.0.26100.33158
Long-term hardening
0/1
HARDENINGImplement application whitelisting on engineering workstations and HMIs to prevent execution of unauthorized binaries
API: /api/v1/advisories/219dc67b-dad9-4c86-9333-c251c81f4631

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Kernel Elevation of Privilege Vulnerability | CVSS 7.8 - OTPulse