Windows Kernel Information Disclosure Vulnerability

Plan PatchCVSS 7.5CVE-2026-50463Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

An out-of-bounds read vulnerability in the Windows Kernel allows an attacker to disclose sensitive kernel memory over the network without authentication. The flaw is in bounds checking that fails to prevent reading memory outside the intended range. All versions of Windows 10, Windows 11, and Windows Server 2019, 2022, and 2025 are affected.

What this means
What could happen
An attacker can read sensitive kernel memory remotely without authentication, potentially exposing encryption keys, credentials, or other confidential data that could be used in follow-up attacks on your industrial systems.
Who's at risk
This affects Windows 10, Windows 11, and Windows Server systems (2019, 2022, 2025) used for engineering workstations, historian servers, HMI systems, and administrative access to your water/electric utility SCADA and control networks. If any of your control system servers or engineering machines run these Windows versions, they are at risk.
How it could be exploited
An attacker sends a specially crafted network packet to a Windows system. The kernel processes the request, reads out-of-bounds memory due to a flaw in bounds checking, and returns the sensitive data back over the network. No special access or credentials are required.
Prerequisites
  • Network access to the affected Windows system
  • No authentication or credentials needed
remotely exploitableno authentication requiredlow complexityhigh CVSS (7.5)
Exploitability
Some exploitation risk — EPSS score 1.0%
Affected products (19)
19 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/3
Do now
0/1
HARDENINGRestrict network access to Windows systems running SCADA workstations, historian servers, or HMI software from untrusted networks using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the July 2026 Windows security update to all affected Windows 10, Windows 11, and Windows Server systems
Long-term hardening
0/1
HARDENINGSegment engineering and administrative workstations from production networks to limit exposure of kernel memory disclosure to critical systems
API: /api/v1/advisories/169b7b1e-6e3e-44cf-98c9-5ba2a0cf027b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.