Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-50396Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free vulnerability in Windows Kernel-Mode Drivers allows an authorized local user to elevate privileges to administrative level. This affects Windows Server 2025 and Windows 11 (versions 24H2, 25H2, and 26H1) for both x64 and ARM64 architectures. Microsoft has released fixes in the 2026-Jul security update.

What this means
What could happen
A user with local access to a Windows system could exploit a kernel driver flaw to gain administrative privileges, potentially allowing them to modify control logic or disable safety monitoring on industrial automation systems running on that machine.
Who's at risk
Water utilities and electric utilities running SCADA systems, HMIs, or process control software on Windows Server 2025, Windows 11 (versions 24H2, 25H2, or 26H1), or Windows Server systems. Any utility where a compromised local user account or remote desktop access could lead to unauthorized system administration privileges.
How it could be exploited
An attacker with a local user account on a Windows machine could trigger a use-after-free condition in a kernel-mode driver to escalate privileges to system/administrator level. This would allow them to run arbitrary code with the highest privileges on the machine, potentially affecting any OT software or HMI running on it.
Prerequisites
  • Local user account on the Windows system
  • Interactive logon or remote desktop access to the machine
  • Windows kernel-mode driver vulnerability must be present (unpatched system)
Local exploitation only (no remote access)Requires valid user credentialsModerate complexity attackAffects Windows operating system kernel
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.8875
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.8875
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.8875
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.8875
Windows Server 2025All versionsBuild 10.0.26100.33158
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2269
Windows 11 Version 26H1 for ARM64-based SystemsAll versionsBuild 10.0.28000.2525
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply Windows 2026-Jul security updates to all affected systems
Long-term hardening
0/2
HARDENINGRestrict local logon privileges on Windows servers running OT software to authorized personnel only
HARDENINGImplement network segmentation to limit access to engineering workstations and HMI servers to trusted networks
API: /api/v1/advisories/ae17a0b2-86a4-4e0f-85dd-1d52dbdb3439

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | CVSS 7 - OTPulse