Windows Kernel Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-50436Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A use-after-free vulnerability in the Windows kernel allows a local user to elevate privileges to administrator level. An attacker with a local user account can execute code with kernel privileges, gaining full system control. Affects Windows Server 2025 (all editions) and Windows 11 versions 24H2, 25H2, and 26H1 (both x64 and ARM64 architectures).

What this means
What could happen
A user with local login access to a Windows Server or Windows 11 system could exploit a memory management flaw in the kernel to gain administrator privileges, potentially allowing unauthorized control of the system and any OT devices or software running on it.
Who's at risk
Water utilities and electric utilities running Windows Server 2025 or Windows 11 systems in OT environments, particularly engineering workstations, HMI (Human-Machine Interface) servers, historian systems, and any systems that control or monitor SCADA infrastructure or industrial processes. Any organization relying on Windows-based data acquisition or control systems should apply these updates.
How it could be exploited
An attacker with a local user account on an affected Windows system (such as an engineering workstation or HMI) executes specially crafted code that triggers a use-after-free condition in the Windows kernel, causing the kernel to execute attacker-controlled code with elevated (administrator) privileges.
Prerequisites
  • Local user account on the affected system
  • Local code execution capability
  • No additional authentication or special configuration required
Low attack complexityRequires local accessAffects multiple Windows versions and architecturesExploitation likely according to vendor assessment
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.8875
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.8875
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.8875
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.8875
Windows Server 2025All versionsBuild 10.0.26100.33158
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2269
Windows 11 Version 26H1 for ARM64-based SystemsAll versionsBuild 10.0.28000.2525
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Windows Server 2025
HOTFIXApply Microsoft's July 2026 security update to all affected Windows Server 2025 and Windows 11 systems
HOTFIXPrioritize patching engineering workstations, HMI systems, and historian servers that run Windows Server 2025 or Windows 11
Long-term hardening
0/2
HARDENINGRestrict local login access to critical OT systems to only authorized personnel with documented business need
HARDENINGMonitor and restrict use of privileged accounts; implement application whitelisting to prevent execution of unauthorized code on OT systems
API: /api/v1/advisories/7c73ac7b-9305-4f9b-a008-33eab2a35451

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Kernel Elevation of Privilege Vulnerability | CVSS 7.8 - OTPulse