Windows Kernel Elevation of Privilege Vulnerability

MonitorCVSS 5.5CVE-2026-50377Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Out-of-bounds read in Windows Kernel that allows an authorized attacker to elevate privileges locally. Affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures. Exploitation assessed as less likely.

What this means
What could happen
A user with local access to a Windows system could exploit an out-of-bounds read in the kernel to gain elevated privileges, potentially allowing them to access sensitive data on systems like HMIs or engineering workstations used to control industrial equipment.
Who's at risk
Any organization running Windows 10, Windows 11, or Windows Server systems should care, particularly those with HMIs (Human Machine Interfaces), engineering workstations, or any Windows-based control system that could be compromised through local access. This affects 32-bit, x64, and ARM64 systems across multiple Windows versions and editions.
How it could be exploited
An attacker with a local user account on the Windows system would trigger the out-of-bounds read in the kernel memory to elevate their privilege level. This could occur if an attacker has physical access to a machine, gains access through a compromised user account, or if malicious code is already running on the system.
Prerequisites
  • Local user account on the Windows system
  • Ability to execute code on the affected system
requires local accesslow complexityno authentication required from privileged account
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Jul security update to Windows 10, Windows 11, or Windows Server systems
Long-term hardening
0/2
HARDENINGRestrict local console and Remote Desktop access to Windows HMIs and engineering workstations to authorized personnel only
HARDENINGDisable local user account creation on systems that do not require it
API: /api/v1/advisories/89e61e15-3165-495f-93e3-f12d31ce9b82

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Kernel Elevation of Privilege Vulnerability | CVSS 5.5 - OTPulse