Windows Kernel Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-50673Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
A null pointer dereference vulnerability in the Windows kernel (CVE-2026-50673) allows a user with local access and limited privileges to elevate to system level. The flaw exists across Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025. Microsoft has released patches for all affected versions and rates exploitation as less likely.
What this means
What could happen
An attacker with local access to a Windows machine could elevate their privileges to system level, allowing them to modify control system applications, access sensitive data, or disrupt operations without triggering standard security controls.
Who's at risk
Windows servers and workstations running Server 2016, 2019, 2022, 2025 or Windows 10/11 used as engineering workstations, HMI systems, or data historians. Any automation infrastructure with Windows-based controllers or edge devices is affected.
How it could be exploited
An attacker with user-level access on the Windows system exploits a null pointer dereference in the kernel to escalate privileges to system/administrator level. The attacker would need interactive local access or an ability to run code as a limited user, then trigger the vulnerable kernel code path to gain full system control.
Prerequisites
- Local user account on the Windows system
- Ability to execute code with limited user privileges
Low attack complexityLocal access requiredRequires user-level privilegesLow EPSS score (0.2%)Not actively exploited
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply the Microsoft July 2026 security update to Windows systems running affected versions (Windows Server 2016, 2019, 2022, 2025; Windows 10/11 all supported versions)
Long-term hardening
0/2HARDENINGReview user access controls and remove unnecessary local user accounts to reduce attack surface
HARDENINGRestrict physical and remote access to engineering workstations and HMI systems to authorized personnel only
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/ff3c5db8-d9f3-417f-9159-4a4d1b8208f8Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.