Windows Kernel Information Disclosure Vulnerability

MonitorCVSS 5.5CVE-2026-50475Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A buffer over-read vulnerability in the Windows kernel allows an authorized local user to read kernel memory and disclose sensitive information. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), and Windows Server 2016, 2019, 2022, and 2025. Microsoft has released patches for all affected versions.

What this means
What could happen
An authorized user on the system could read sensitive information from kernel memory, potentially exposing passwords, encryption keys, or other confidential data stored in system memory. This is a local information disclosure issue, not remote code execution.
Who's at risk
Windows IT administrators and OT systems running Windows 10, Windows 11, or Windows Server 2016, 2019, 2022, or 2025. This includes industrial workstations, engineering laptops, HMI servers, and any Windows-based OT or IT infrastructure. Any system where sensitive data or credentials are handled in kernel memory is at risk of exposure.
How it could be exploited
An attacker with a regular user account on the machine could trigger a buffer over-read in the Windows kernel through a crafted local API call, allowing them to read memory contents that should not be accessible to their privilege level.
Prerequisites
  • Local access to the system with a non-administrative user account
  • Ability to execute code as a local user (e.g., via RDP, console, or application running with user privileges)
  • No special network access required
No authentication required (local user account is sufficient)Low complexity exploitationAffects multiple Windows versionsInformation disclosure of kernel memory
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXInstall the July 2026 Windows security update or later for your Windows version and architecture (see affected products list for specific build numbers)
API: /api/v1/advisories/73473f6c-575b-4da5-b565-3116fc07d4eb

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.