Windows Kernel Elevation of Privilege Vulnerability

Plan PatchCVSS 8.8CVE-2026-50477Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. Affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025.

What this means
What could happen
A user with standard credentials on a Windows workstation or server could run commands with system-level privileges, potentially controlling PLCs, HMIs, data historians, or other OT systems running on or communicating with affected Windows systems.
Who's at risk
Any organization running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 systems that are part of or connected to operational technology infrastructure. This includes HMI workstations, data historian servers, domain controllers managing OT networks, and engineering workstations controlling PLCs and SCADA systems.
How it could be exploited
An attacker with a local user account on a Windows system triggers a heap buffer overflow in the kernel through a specially crafted request, gaining SYSTEM privileges. From there, the attacker can execute arbitrary code with the highest privilege level on the machine.
Prerequisites
  • Local user account on the affected Windows system
  • Ability to run a malicious application or trigger kernel code through local API call
Low complexity exploitationRequires valid local credentialsHigh privilege impact (SYSTEM-level access)Affects common Windows versions across IT/OT environments
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Jul Windows security update to all affected systems. Update to the specific build versions listed for your Windows version and architecture.
Long-term hardening
0/2
HARDENINGRestrict local logon to Windows workstations and servers in your OT network to authorized engineering and administrative personnel only.
HARDENINGImplement application whitelisting on OT-connected Windows systems to prevent unauthorized executables from running.
API: /api/v1/advisories/2c3c1bef-1ed9-423e-b19d-95fea180d6bd

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Kernel Elevation of Privilege Vulnerability | CVSS 8.8 - OTPulse