Windows Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 8.8CVE-2026-50670Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

An out-of-bounds read in Windows Kernel allows an authorized attacker with a valid local user account to elevate privileges and gain SYSTEM-level access. The vulnerability affects Windows 10 (versions 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2019, 2022, and 2025 across 32-bit, 64-bit, and ARM64 platforms. Microsoft has released patches for all affected versions.

What this means
What could happen
An attacker with a local user account could exploit an out-of-bounds read in the Windows kernel to gain administrative privileges on the system, allowing them to install malware, disable security controls, or take full control of an operator workstation or HMI server.
Who's at risk
Windows operator workstations, HMI (Human Machine Interface) servers, and any Windows-based control system components running Windows 10 (versions 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2019, 2022, or 2025. This affects both 32-bit, 64-bit, and ARM64 architectures.
How it could be exploited
The attacker must have a valid user account on the Windows system and can trigger an out-of-bounds read in the kernel through local API calls or application interaction, bypassing privilege checks to escalate to SYSTEM/administrator level.
Prerequisites
  • Valid local user account on the Windows system
  • Local code execution capability (ability to run applications on the machine)
Local privilege escalationRequires valid user credentialsLow complexity attackAffects operator workstations and control servers
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (19)
19 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXApply the 2026-Jul security update to all Windows systems. Specific build targets: Windows 10 1809 (10.0.17763.9020), Windows 10 21H2 (10.0.19044.7548), Windows 10 22H2 (10.0.19045.7548), Windows 11 24H2 (10.0.26100.8875), Windows 11 25H2 (10.0.26200.8875), Windows 11 26H1 (10.0.28000.2525), Windows Server 2019 (10.0.17763.9020), Windows Server 2022 (10.0.20348.5386), Windows Server 2025 (10.0.26100.33158).
API: /api/v1/advisories/2f650983-607e-4b9b-a85d-c5ec08305c9d

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Win32k Elevation of Privilege Vulnerability | CVSS 8.8 - OTPulse