Windows Kernel Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-50399Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

An out-of-bounds read vulnerability in the Windows Kernel allows an authorized local user to escalate privileges to SYSTEM level. The vulnerability affects Windows Server 2022, 2025; Windows 10 (versions 21H2 and 22H2) for 32-bit, x64, and ARM64 systems; and Windows 11 (versions 24H2, 25H2, and 26H1) for x64 and ARM64 systems. Microsoft has released patches for all affected versions and rates exploitation as less likely.

What this means
What could happen
A user with local access to a Windows system running vulnerable versions could escalate their privileges to system level, potentially allowing them to modify critical operations or install malicious software that persists across reboots.
Who's at risk
Water utilities and municipal electric providers should prioritize Windows Server systems running operational technology applications, engineering workstations used to configure SCADA/HMI systems, and any Windows-based data historians or historian clients. Windows 10 and Windows 11 systems used for administrative and monitoring tasks are also affected. The main concern is systems where local users can interact with critical control software.
How it could be exploited
An attacker with a regular user account on an affected Windows system could trigger an out-of-bounds read in the kernel to escalate privileges to SYSTEM level. This requires local code execution capability (the attacker must be able to run code on the machine) but no special network access.
Prerequisites
  • Local user account on affected Windows system
  • Ability to execute code (e.g., via a remote access tool, application vulnerability, or physical access)
Privilege escalation vulnerabilityRequires local accessLow exploit complexityAffects all Windows versions
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (15)
15 with fix
ProductAffected VersionsFix Status
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows 10 Version 21H2 for 32-bit SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 21H2 for ARM64-based SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 21H2 for x64-based SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 22H2 for x64-based SystemsAll versionsBuild 10.0.19045.7548
Windows 10 Version 22H2 for ARM64-based SystemsAll versionsBuild 10.0.19045.7548
Windows 10 Version 22H2 for 32-bit SystemsAll versionsBuild 10.0.19045.7548
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply 2026-Jul Windows security update to all affected Windows systems
Long-term hardening
0/2
HARDENINGRestrict user privileges: ensure users run with standard user accounts rather than administrator accounts where possible
HARDENINGEnforce application whitelisting on Windows systems to reduce the risk of unauthorized code execution
API: /api/v1/advisories/67794323-9aff-4726-9f21-5530527b1c29

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Kernel Elevation of Privilege Vulnerability | CVSS 7.8 - OTPulse