Windows Server Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-56177Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A use-after-free condition in the Windows kernel allows a user with local access to escalate privileges to SYSTEM level. This vulnerability affects Windows Server 2016 through 2025, Windows 10 (versions 1607, 1809, 21H2, 22H2), and Windows 11 (versions 23H2, 24H2, 25H2, 26H1) on 32-bit, x64, and ARM64 systems, as well as Server Core installations.

What this means
What could happen
A user with local access to Windows Server or Windows 10 could exploit this vulnerability to run commands with system privileges, potentially altering critical process configurations, disabling safety controls, or stopping industrial applications.
Who's at risk
Windows Server 2016, 2019, 2022, and 2025 (standard and Server Core installations), and Windows 10/11 systems used in OT environments for supervisory control, HMIs, data collection servers, or engineering workstations. This affects any facility running these systems in process automation, utility operations, or facility management roles.
How it could be exploited
An attacker with a local user account on the server runs a specially crafted program that triggers a use-after-free condition in the Windows kernel. This escalates their privileges to SYSTEM level, allowing them to take full control of the machine and any connected industrial processes.
Prerequisites
  • Local user account on Windows Server or Windows 10 system
  • Low user privileges (PR:L)
  • No user interaction required
Local escalation of privilegeLow attack complexityRequires local account accessAffects all recent Windows Server versions
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/3
Do now
0/1
HARDENINGRestrict local interactive logon and remote desktop access to Windows Server systems to only authorized engineering and maintenance personnel
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXInstall the September 2026 Windows security update for your Windows Server and Windows 10 versions (see fixed build numbers in affected products list)
WORKAROUNDEnable Windows Defender Application Control or AppLocker to restrict which programs can execute on Windows Server systems
API: /api/v1/advisories/7c09491b-dc38-44f9-850d-51661650977e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.