Windows Kernel Elevation of Privilege Vulnerability

MonitorCVSS 6.8CVE-2026-54132Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorPhysical
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Heap-based buffer overflow in Windows Kernel allows unauthorized elevation of privileges with a physical attack vector.

What this means
What could happen
An attacker with physical access to a Windows workstation or server could escalate privileges to run commands at the highest system level, potentially taking control of critical engineering systems or data on that machine.
Who's at risk
Organizations using Windows 10 or Windows Server 2016/2019 systems should be concerned if these machines are in unsecured physical locations (equipment rooms, unmanned facilities, kiosks). This includes SCADA systems, engineering workstations, and historian servers running Windows. Desktop workstations in secure offices are at lower risk.
How it could be exploited
An attacker must have direct physical access to the machine (e.g., local USB port, keyboard, or console). They exploit a heap-based buffer overflow in the kernel to escalate from a low-privilege account to system-level access.
Prerequisites
  • Physical access to the device (local, not remote)
  • Ability to execute code or interact with a vulnerable kernel interface
  • User account (no special credentials required)
Physical attack required (lowers exposure in typical offices)No authentication barrierLow attack complexityAffects Windows workstations and servers
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (20)
20 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows 10 Version 21H2 for 32-bit SystemsAll versionsBuild 10.0.19044.7548
Remediation & Mitigation
0/3
Do now
0/1
HARDENINGRestrict physical access to Windows machines in control rooms, equipment rooms, and data centers using locked enclosures or badge-controlled areas
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply the 2026-Jul (July 2026) Windows security update to all Windows 10 and Windows Server 2016/2019 systems
Long-term hardening
0/1
HARDENINGEnable BIOS/UEFI firmware password protection to prevent unauthorized boot or BIOS modification
API: /api/v1/advisories/2490669a-4916-4294-a722-147dd1bca334

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Kernel Elevation of Privilege Vulnerability | CVSS 6.8 - OTPulse