Windows Kernel Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-50399Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
An out-of-bounds read vulnerability in the Windows Kernel allows an authorized local user to escalate privileges to SYSTEM level. The vulnerability affects Windows Server 2022, 2025; Windows 10 (versions 21H2 and 22H2) for 32-bit, x64, and ARM64 systems; and Windows 11 (versions 24H2, 25H2, and 26H1) for x64 and ARM64 systems. Microsoft has released patches for all affected versions and rates exploitation as less likely.
What this means
What could happen
A user with local access to a Windows system running vulnerable versions could escalate their privileges to system level, potentially allowing them to modify critical operations or install malicious software that persists across reboots.
Who's at risk
Water utilities and municipal electric providers should prioritize Windows Server systems running operational technology applications, engineering workstations used to configure SCADA/HMI systems, and any Windows-based data historians or historian clients. Windows 10 and Windows 11 systems used for administrative and monitoring tasks are also affected. The main concern is systems where local users can interact with critical control software.
How it could be exploited
An attacker with a regular user account on an affected Windows system could trigger an out-of-bounds read in the kernel to escalate privileges to SYSTEM level. This requires local code execution capability (the attacker must be able to run code on the machine) but no special network access.
Prerequisites
- Local user account on affected Windows system
- Ability to execute code (e.g., via a remote access tool, application vulnerability, or physical access)
Privilege escalation vulnerabilityRequires local accessLow exploit complexityAffects all Windows versions
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (15)
15 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply 2026-Jul Windows security update to all affected Windows systems
Long-term hardening
0/2HARDENINGRestrict user privileges: ensure users run with standard user accounts rather than administrator accounts where possible
HARDENINGEnforce application whitelisting on Windows systems to reduce the risk of unauthorized code execution
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/67794323-9aff-4726-9f21-5530527b1c29Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.