Windows Kernel Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-50459Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityHigh
User InteractionRequired
Summary

A use-after-free vulnerability in the Windows Kernel allows a local user with unprivileged access to escalate privileges to SYSTEM level. Exploitation requires user interaction such as opening a malicious file on an affected Windows system. The vulnerability affects Windows Server 2022, 2025, all versions of Windows 10, and all versions of Windows 11 across 32-bit, x64, and ARM64 architectures. Microsoft has released patches for all affected platforms.

What this means
What could happen
A local attacker with unprivileged access to a Windows machine running vulnerable versions could escalate privileges to system level, potentially gaining full control of the device. In an industrial setting, this could compromise operator workstations, engineering stations, or servers that communicate with control systems.
Who's at risk
This affects Windows Server 2022, 2025, Windows 10 and Windows 11 systems across all supported architectures. In a municipal water or electric utility, this primarily impacts operator workstations, engineering laptops connected to design networks, and administrative servers that staff use to manage or communicate with industrial control systems. Any Windows machine that could reach or influence your OT network is at risk.
How it could be exploited
An attacker must already have interactive local access to a vulnerable Windows system (e.g., logged-in unprivileged user account). They would exploit a use-after-free flaw in the kernel to trigger privilege escalation. This requires user interaction (e.g., opening a malicious file) to execute the exploit code.
Prerequisites
  • Local user account on affected Windows system
  • User interaction to trigger exploit (e.g., opening file)
  • Unprivileged user context
Requires local accessLow EPSS score (less than 1%)Requires user interaction
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (15)
15 with fix
ProductAffected VersionsFix Status
Windows Server 2022All versionsBuild 10.0.20348.5386
Windows 10 Version 21H2 for 32-bit SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 21H2 for ARM64-based SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 21H2 for x64-based SystemsAll versionsBuild 10.0.19044.7548
Windows 10 Version 22H2 for x64-based SystemsAll versionsBuild 10.0.19045.7548
Windows 10 Version 22H2 for ARM64-based SystemsAll versionsBuild 10.0.19045.7548
Windows 10 Version 22H2 for 32-bit SystemsAll versionsBuild 10.0.19045.7548
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Remediation & Mitigation
0/10
Schedule — requires maintenance window
0/8

Patching may require device reboot — plan for process interruption

Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5386 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 (all editions) to Build 10.0.26100.33158 or later
All products
HOTFIXUpdate Windows 10 Version 21H2 (32-bit, ARM64, x64) to Build 10.0.19044.7548 or later
HOTFIXUpdate Windows 10 Version 22H2 (32-bit, ARM64, x64) to Build 10.0.19045.7548 or later
HOTFIXUpdate Windows 11 Version 24H2 (x64, ARM64) to Build 10.0.26100.8875 or later
HOTFIXUpdate Windows 11 Version 25H2 (x64, ARM64) to Build 10.0.26200.8875 or later
HOTFIXUpdate Windows 11 Version 26H1 (x64) to Build 10.0.28000.2269 or later
HOTFIXUpdate Windows 11 Version 26H1 (ARM64) to Build 10.0.28000.2525 or later
Long-term hardening
0/2
HARDENINGRestrict local console and RDP access to Windows systems to authorized personnel only
HARDENINGUse application whitelisting to prevent execution of untrusted files on operator workstations and engineering stations
API: /api/v1/advisories/3bdf4781-684a-4f14-9b1f-3a2eef3a1121

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Kernel Elevation of Privilege Vulnerability | CVSS 7 - OTPulse