Windows Kernel Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-50484Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A heap-based buffer overflow vulnerability exists in the Windows kernel that allows an authorized local user (non-admin) to escalate their privileges to system level. The vulnerability is in kernel memory management and can be triggered by a specially crafted application running on the affected system.

What this means
What could happen
An attacker with a local user account on a Windows server or workstation could execute this vulnerability to gain system-level privileges, potentially allowing them to modify system configurations, access sensitive data, or disrupt operations on devices that run your critical infrastructure.
Who's at risk
Windows servers and workstations used in municipal water and electric utility operations, particularly Windows Server 2019, 2022, and 2025 installations running SCADA systems, historian servers, engineering workstations, or HMI platforms. Windows 10 and 11 endpoints used by operators and engineers are also affected.
How it could be exploited
An attacker with a valid local user account (non-admin) runs a specially crafted application that triggers a heap buffer overflow in the Windows kernel. This overflow allows the attacker to escalate their privileges from standard user to system/administrator level.
Prerequisites
  • Valid local user account on the affected Windows system (non-administrator credentials required)
  • Local code execution capability (ability to run malicious executable on the system)
Local privilege escalationRequires valid user accountLow complexity exploitationAffects all Windows kernel versions across multiple OS versions
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (19)
19 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXPrioritize patching Windows Server 2019, 2022, and 2025 systems used in OT networks
All products
HOTFIXApply the 2026-Jul Windows security update to all affected Windows systems
Long-term hardening
0/2
HARDENINGRestrict local interactive logon rights to authorized personnel only, using Group Policy or local security policies
HARDENINGImplement privilege management controls to prevent unprivileged users from executing arbitrary applications
API: /api/v1/advisories/ba7fc61f-c9d6-4040-a5fc-b238f4b3c2e3

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Kernel Elevation of Privilege Vulnerability | CVSS 7.8 - OTPulse