Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 8.8CVE-2026-50489Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Heap-based buffer overflow in Windows Win32K kernel component allows an authorized local attacker to elevate privileges to system level. Affects all current and recent versions of Windows 10, Windows 11, and Windows Server 2016 through 2025. Exploitation is assessed as "more likely" and the vulnerability is actively being exploited.

What this means
What could happen
An attacker with standard user credentials could run commands with system-level privileges on a Windows computer, potentially compromising control system workstations or HMIs. This could allow unauthorized modification of process configurations or shutdown of critical operations.
Who's at risk
Organizations running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 environments, particularly those used for HMI/SCADA workstations, engineering stations, or domain controllers in industrial facilities. Most critical for systems where standard users have shell access to operational technology networks.
How it could be exploited
An attacker with a valid user account on the Windows system exploits a heap-based buffer overflow in the Win32K kernel component to bypass privilege restrictions and execute code with administrator rights.
Prerequisites
  • Local user account credentials required
  • Physical or network access to an interactive Windows session
  • Affected Windows OS version installed
locally exploitable (requires user account)low complexity attackhigh CVSS score (8.8)affects multiple Windows versionsactively being exploited in the wild
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/3

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply the July 2026 Windows security update patch to all affected systems: Windows 10, Windows 11, Windows Server 2016/2019/2022/2025
All products
HARDENINGRestrict local user account creation and enforce strong password policies to limit user accounts that could exploit this vulnerability
HARDENINGMonitor for unauthorized privilege escalation attempts on Windows systems using event logs or EDR tools
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate control system workstations and HMIs, restricting which users and systems can access them
API: /api/v1/advisories/863c56fb-b65e-4172-b102-e92cdade538b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.