Windows Server Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-56177Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A use-after-free condition in the Windows kernel allows a user with local access to escalate privileges to SYSTEM level. This vulnerability affects Windows Server 2016 through 2025, Windows 10 (versions 1607, 1809, 21H2, 22H2), and Windows 11 (versions 23H2, 24H2, 25H2, 26H1) on 32-bit, x64, and ARM64 systems, as well as Server Core installations.
What this means
What could happen
A user with local access to Windows Server or Windows 10 could exploit this vulnerability to run commands with system privileges, potentially altering critical process configurations, disabling safety controls, or stopping industrial applications.
Who's at risk
Windows Server 2016, 2019, 2022, and 2025 (standard and Server Core installations), and Windows 10/11 systems used in OT environments for supervisory control, HMIs, data collection servers, or engineering workstations. This affects any facility running these systems in process automation, utility operations, or facility management roles.
How it could be exploited
An attacker with a local user account on the server runs a specially crafted program that triggers a use-after-free condition in the Windows kernel. This escalates their privileges to SYSTEM level, allowing them to take full control of the machine and any connected industrial processes.
Prerequisites
- Local user account on Windows Server or Windows 10 system
- Low user privileges (PR:L)
- No user interaction required
Local escalation of privilegeLow attack complexityRequires local account accessAffects all recent Windows Server versions
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1HARDENINGRestrict local interactive logon and remote desktop access to Windows Server systems to only authorized engineering and maintenance personnel
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXInstall the September 2026 Windows security update for your Windows Server and Windows 10 versions (see fixed build numbers in affected products list)
WORKAROUNDEnable Windows Defender Application Control or AppLocker to restrict which programs can execute on Windows Server systems
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/7c09491b-dc38-44f9-850d-51661650977eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.