Windows Win32k Elevation of Privilege Vulnerability
Plan PatchCVSS 8.8CVE-2026-50670Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
An out-of-bounds read in Windows Kernel allows an authorized attacker with a valid local user account to elevate privileges and gain SYSTEM-level access. The vulnerability affects Windows 10 (versions 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2019, 2022, and 2025 across 32-bit, 64-bit, and ARM64 platforms. Microsoft has released patches for all affected versions.
What this means
What could happen
An attacker with a local user account could exploit an out-of-bounds read in the Windows kernel to gain administrative privileges on the system, allowing them to install malware, disable security controls, or take full control of an operator workstation or HMI server.
Who's at risk
Windows operator workstations, HMI (Human Machine Interface) servers, and any Windows-based control system components running Windows 10 (versions 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2019, 2022, or 2025. This affects both 32-bit, 64-bit, and ARM64 architectures.
How it could be exploited
The attacker must have a valid user account on the Windows system and can trigger an out-of-bounds read in the kernel through local API calls or application interaction, bypassing privilege checks to escalate to SYSTEM/administrator level.
Prerequisites
- Valid local user account on the Windows system
- Local code execution capability (ability to run applications on the machine)
Local privilege escalationRequires valid user credentialsLow complexity attackAffects operator workstations and control servers
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (19)
19 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXApply the 2026-Jul security update to all Windows systems. Specific build targets: Windows 10 1809 (10.0.17763.9020), Windows 10 21H2 (10.0.19044.7548), Windows 10 22H2 (10.0.19045.7548), Windows 11 24H2 (10.0.26100.8875), Windows 11 25H2 (10.0.26200.8875), Windows 11 26H1 (10.0.28000.2525), Windows Server 2019 (10.0.17763.9020), Windows Server 2022 (10.0.20348.5386), Windows Server 2025 (10.0.26100.33158).
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/2f650983-607e-4b9b-a85d-c5ec08305c9dGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.