Windows Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-50688Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free flaw in the Windows kernel allows a local user with standard privileges to escalate to system administrator level. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 (including Server Core installations). An authorized attacker with local access can exploit this to run arbitrary code with kernel privileges.

What this means
What could happen
A user with local access to a Windows workstation or server could run commands with system-level privileges, potentially allowing them to modify critical plant control software, disable safety systems, or alter SCADA/HMI configurations without authorization.
Who's at risk
Water authorities and utilities running Windows workstations or servers for SCADA, HMI, engineering software, or historian systems. This includes control room PCs, remote terminal units (RTUs), engineering workstations, and supervisory servers on Windows 10 or Windows Server 2016, 2019, 2022, or 2025.
How it could be exploited
An attacker with a regular user account on a Windows machine (such as a plant floor workstation or engineering station) could exploit a memory flaw in the Windows kernel to run arbitrary commands with administrator privileges. No network access is required—the attacker must have local interactive access.
Prerequisites
  • Local user account on the affected Windows machine
  • Ability to execute code (through application use or script)
  • Physical or remote desktop access to log in locally
Requires local accessLow exploit complexityHigh impact—allows system privilege escalationAffects all Windows versions in active useExploitation likely but not currently actively weaponized
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/4
Do now
0/1
HARDENINGRestrict local login access to Windows machines to authorized plant personnel only; disable or remove unnecessary user accounts
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXApply the July 2026 Windows security update to all affected Windows 10, Windows 11, and Windows Server systems
HOTFIXPrioritize patching Windows Server systems that host SCADA, HMI, or engineering workstations
Long-term hardening
0/1
HARDENINGImplement account privilege separation so that plant operators and engineers use standard user accounts rather than administrator accounts for daily work
API: /api/v1/advisories/86282fc3-411a-4567-b0c8-45da66c7a08f

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.