Windows Kernel Elevation of Privilege Vulnerability

Plan PatchCVSS 7.1CVE-2026-50354Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A use-after-free vulnerability in the Windows Kernel allows an authorized local user to elevate privileges to system level. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, and 22H2), Windows 11 (versions 24H2, 25H2, and 26H1), and Windows Server 2016, 2019, 2022, and 2025 on 32-bit, x64-based, and ARM64-based systems. Microsoft has released fixes for all supported versions.

What this means
What could happen
A user with local access to a Windows computer or server could exploit this vulnerability to gain administrative privileges, potentially allowing them to install malware, modify operational software, or disable security controls on systems running critical plant applications.
Who's at risk
Windows IT administrators and OT personnel managing Windows servers or engineering workstations running Windows 10, Windows 11, or Windows Server 2016 through 2025 should apply this update. This includes SCADA servers, historian systems, HMI workstations, and any other industrial control systems or critical infrastructure running on Windows platforms.
How it could be exploited
An attacker with a local user account on a Windows 10 or Windows Server system could trigger a use-after-free condition in the kernel to escalate their privileges to system level. This requires the attacker to already have local access (e.g., through a compromised account or physical access to a workstation).
Prerequisites
  • Local user account credentials on the affected Windows system
  • Ability to execute code or trigger the vulnerable code path locally
low exploit probability (0.2% EPSS)requires local accessaffects all supported Windows versionshigh impact if exploited on critical systems
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the July 2026 Windows security update for your Windows version (Build 10.0.17763.9020 for Windows 10 1809 / Server 2019, Build 10.0.20348.5386 for Server 2022, Build 10.0.19044.7548 for Windows 10 21H2, Build 10.0.19045.7548 for Windows 10 22H2, Build 10.0.26100.33158 for Server 2025, Build 10.0.26100.8875 for Windows 11 24H2, Build 10.0.26200.8875 for Windows 11 25H2, Build 10.0.28000.2269 or .2525 for Windows 11 26H1, Build 10.0.14393.9339 for Windows 10 1607 / Server 2016)
API: /api/v1/advisories/a3291e3b-e259-4bad-b8fc-8c11de90d850

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.