Windows Kernel Elevation of Privilege Vulnerability
Plan PatchCVSS 8.8CVE-2026-50477Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. Affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025.
What this means
What could happen
A user with standard credentials on a Windows workstation or server could run commands with system-level privileges, potentially controlling PLCs, HMIs, data historians, or other OT systems running on or communicating with affected Windows systems.
Who's at risk
Any organization running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 systems that are part of or connected to operational technology infrastructure. This includes HMI workstations, data historian servers, domain controllers managing OT networks, and engineering workstations controlling PLCs and SCADA systems.
How it could be exploited
An attacker with a local user account on a Windows system triggers a heap buffer overflow in the kernel through a specially crafted request, gaining SYSTEM privileges. From there, the attacker can execute arbitrary code with the highest privilege level on the machine.
Prerequisites
- Local user account on the affected Windows system
- Ability to run a malicious application or trigger kernel code through local API call
Low complexity exploitationRequires valid local credentialsHigh privilege impact (SYSTEM-level access)Affects common Windows versions across IT/OT environments
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the 2026-Jul Windows security update to all affected systems. Update to the specific build versions listed for your Windows version and architecture.
Long-term hardening
0/2HARDENINGRestrict local logon to Windows workstations and servers in your OT network to authorized engineering and administrative personnel only.
HARDENINGImplement application whitelisting on OT-connected Windows systems to prevent unauthorized executables from running.
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/2c3c1bef-1ed9-423e-b19d-95fea180d6bdGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.