Windows Win32k Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-50688Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
A use-after-free flaw in the Windows kernel allows a local user with standard privileges to escalate to system administrator level. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 (including Server Core installations). An authorized attacker with local access can exploit this to run arbitrary code with kernel privileges.
What this means
What could happen
A user with local access to a Windows workstation or server could run commands with system-level privileges, potentially allowing them to modify critical plant control software, disable safety systems, or alter SCADA/HMI configurations without authorization.
Who's at risk
Water authorities and utilities running Windows workstations or servers for SCADA, HMI, engineering software, or historian systems. This includes control room PCs, remote terminal units (RTUs), engineering workstations, and supervisory servers on Windows 10 or Windows Server 2016, 2019, 2022, or 2025.
How it could be exploited
An attacker with a regular user account on a Windows machine (such as a plant floor workstation or engineering station) could exploit a memory flaw in the Windows kernel to run arbitrary commands with administrator privileges. No network access is required—the attacker must have local interactive access.
Prerequisites
- Local user account on the affected Windows machine
- Ability to execute code (through application use or script)
- Physical or remote desktop access to log in locally
Requires local accessLow exploit complexityHigh impact—allows system privilege escalationAffects all Windows versions in active useExploitation likely but not currently actively weaponized
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/1HARDENINGRestrict local login access to Windows machines to authorized plant personnel only; disable or remove unnecessary user accounts
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXApply the July 2026 Windows security update to all affected Windows 10, Windows 11, and Windows Server systems
HOTFIXPrioritize patching Windows Server systems that host SCADA, HMI, or engineering workstations
Long-term hardening
0/1HARDENINGImplement account privilege separation so that plant operators and engineers use standard user accounts rather than administrator accounts for daily work
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/86282fc3-411a-4567-b0c8-45da66c7a08fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.