Windows SMB Server Elevation of Privilege Vulnerability

Plan PatchCVSS 8.8CVE-2026-50360Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A flaw in the Windows SMB Server authentication algorithm allows an authorized user to elevate their privileges over the network. An attacker with valid SMB credentials can bypass privilege checks and gain administrative access without requiring elevated credentials. The vulnerability affects Windows Server 2022, 2025, Windows 10 (versions 21H2, 22H2), and Windows 11 (versions 24H2, 25H2, 26H1).

What this means
What could happen
An authorized user with valid SMB credentials could escalate their privileges on Windows servers and workstations, potentially gaining administrative access and the ability to alter system configurations or access sensitive data across your network.
Who's at risk
All organizations running Windows Server 2022, 2025, Windows 10 (all recent versions), or Windows 11 (all recent versions) are affected. This impacts domain-joined workstations and servers used for file sharing, print services, or remote administration. OT environments using Windows-based HMI systems, engineering workstations, or data historian servers are at risk if they allow SMB access from user networks or have mixed IT/OT connectivity.
How it could be exploited
An attacker with valid domain or local credentials connects to the SMB service (port 445) on a Windows system. The attacker sends a specially crafted authentication request that exploits a flaw in the authentication algorithm, allowing them to bypass privilege checks and gain elevated access without requiring admin credentials.
Prerequisites
  • Valid SMB credentials (domain user or local account)
  • Network access to port 445 (SMB) on affected Windows systems
  • Target system running one of the listed Windows versions
remotely exploitablerequires valid credentialsaffects all supported Windows versionshigh CVSS score (8.8)
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (15)
15 with fix
ProductAffected VersionsFix Status
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows 10 Version 21H2 for 32-bit SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 21H2 for ARM64-based SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 21H2 for x64-based SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 22H2 for x64-based SystemsAll versionsBuild 10.0.19045.7548
Windows 10 Version 22H2 for ARM64-based SystemsAll versionsBuild 10.0.19045.7548
Windows 10 Version 22H2 for 32-bit SystemsAll versionsBuild 10.0.19045.7548
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Remediation & Mitigation
0/8
Do now
0/1
WORKAROUNDRestrict SMB access (port 445) at the firewall to only authorized subnets and jump hosts
Schedule — requires maintenance window
0/7

Patching may require device reboot — plan for process interruption

Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5386 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33158 or later
All products
HOTFIXUpdate Windows 10 Version 21H2 to Build 10.0.19044.7548 or later
HOTFIXUpdate Windows 10 Version 22H2 to Build 10.0.19045.7548 or later
HOTFIXUpdate Windows 11 Version 24H2 to Build 10.0.26100.8875 or later
HOTFIXUpdate Windows 11 Version 25H2 to Build 10.0.26200.8875 or later
HOTFIXUpdate Windows 11 Version 26H1 to Build 10.0.28000.2269 (x64) or Build 10.0.28000.2525 (ARM64) or later
API: /api/v1/advisories/5fe84751-1aa9-4307-b445-02138428310c

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.