Windows Win32k Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-54986Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A heap-based buffer overflow exists in the Windows Win32K graphics kernel subsystem. An authorized user with local logon access could provide specially crafted input that triggers the overflow, allowing them to execute code with elevated system privileges and bypass normal access controls.
What this means
What could happen
A logged-in user on an affected Windows system could exploit a heap buffer overflow in the graphics subsystem to gain elevated privileges, allowing them to install software, modify settings, or access sensitive data that requires admin rights.
Who's at risk
Windows servers and workstations running versions 10.0.14393 through 10.0.28000, including Windows Server 2016, 2019, 2022, 2025, and Windows 10/11 systems. Affects both 32-bit, 64-bit, and ARM64 architectures. Any organization using affected Windows systems needs to apply patches.
How it could be exploited
An attacker with a user account on the target Windows system could craft a malicious input to the Win32K graphics kernel that triggers a heap buffer overflow. By doing so, they could execute arbitrary code with higher privileges, bypassing normal access controls.
Prerequisites
- Valid user account on the affected Windows system
- Local access to the machine (interactive logon or remote desktop)
- No additional software or special configuration required
Low complexity attackAffects multiple Windows versions across 9+ yearsLocally exploitable with user-level credentials
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/1HOTFIXInstall the July 2026 Windows security update for your Windows version
Long-term hardening
0/3HARDENINGRestrict local interactive logon to trusted personnel only
HARDENINGDisable unnecessary remote access protocols (RDP) if not required for operations
HARDENINGApply Windows security group policies to limit privilege escalation vectors
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/4717a1d0-0e21-40c2-9c05-5037b590de99Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.