Windows Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 8.8CVE-2026-50687Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A use-after-free vulnerability in the Windows kernel allows a local attacker with user-level privileges to elevate their access to administrative level. The flaw exists in the Win32k subsystem and affects Windows Server 2025 and Windows 11 versions 24H2, 25H2, and 26H1 across x64 and ARM64 platforms. Microsoft has released fixes for all affected versions.

What this means
What could happen
A local attacker with user-level access can exploit a flaw in the Windows kernel to gain administrative privileges on the affected system, potentially allowing them to install malware, modify critical files, or disable security controls.
Who's at risk
This vulnerability affects servers and workstations running Windows Server 2025 and Windows 11 (versions 24H2, 25H2, and 26H1) on both x64 and ARM64 architectures. Any organization using these Windows platforms should apply the update, particularly those running critical infrastructure or control systems on Windows-based servers.
How it could be exploited
An attacker with a local user account runs a specially crafted program that triggers a use-after-free condition in the Windows kernel. The kernel memory corruption allows the attacker to escalate their privileges from user-level to system/administrative level, bypassing access controls.
Prerequisites
  • Local user account on the affected Windows system
  • Ability to execute arbitrary code on the system
Low complexity exploitationLocal access required (reduces risk in well-segmented networks)High impact if exploited (administrative privilege gain)
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.8875
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.8875
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.8875
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.8875
Windows Server 2025All versionsBuild 10.0.26100.33158
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2269
Windows 11 Version 26H1 for ARM64-based SystemsAll versionsBuild 10.0.28000.2525
Remediation & Mitigation
0/3
Do now
0/1
HARDENINGRestrict local user account creation and access to only trusted personnel
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Jul security update to all affected Windows Server and Windows 11 systems
Long-term hardening
0/1
HARDENINGReview and enforce application allowlisting or code execution policies to prevent unauthorized program execution
API: /api/v1/advisories/13c7a0b9-882e-4e5a-b3ff-2928338d8c3e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Win32k Elevation of Privilege Vulnerability | CVSS 8.8 - OTPulse