Win32k Elevation of Privilege Vulnerability
MonitorCVSS 6.2CVE-2026-57095Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A vulnerability in Windows Win32k kernel component allows exposure of sensitive kernel memory information. An attacker with local access can read protected kernel memory and use the exposed addresses to bypass security protections and gain administrative privilege on the system. This affects Windows 10, Windows 11, and Windows Server 2016 through 2025 across all processor architectures.
What this means
What could happen
An attacker with local access to a Windows system could read sensitive kernel information and use it to gain administrative privileges, potentially allowing them to modify control logic or disable monitoring on systems running HMI software or engineering workstations.
Who's at risk
Organizations running Windows 10, Windows 11, or Windows Server 2016-2025 on engineering workstations, HMI systems, or other IT infrastructure in water utilities and electric utilities are affected. This includes both 32-bit, x64, and ARM64 systems. The risk is highest for systems where operators or technicians have local access without strict administrative controls.
How it could be exploited
An attacker must be present on the Windows machine locally (no remote access). They trigger a Win32k kernel information leak vulnerability, which exposes memory addresses needed to bypass protections. Using this information, they launch a privilege escalation exploit to gain administrative access.
Prerequisites
- Local access to the Windows system
- Ability to run code on the machine (user account or higher)
- No authentication required beyond local logon
No authentication required for local userLow complexity attackAffects kernel memoryPrivilege escalation possible
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/11
Schedule — requires maintenance window
0/10Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9020 or later
Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9339 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5386 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 and Server Core to Build 10.0.26100.33158 or later
All products
HOTFIXUpdate Windows 10 Version 1809 32-bit systems to Build 10.0.17763.9020 or later
HOTFIXUpdate Windows 10 Version 1809 x64-based systems to Build 10.0.17763.9020 or later
HOTFIXUpdate Windows 10 Version 21H2 (32-bit, x64, ARM64) to Build 10.0.19044.7548 or later
HOTFIXUpdate Windows 10 Version 22H2 (32-bit, x64, ARM64) to Build 10.0.19045.7548 or later
HOTFIXUpdate Windows 11 Version 24H2 and 25H2 (x64, ARM64) to Build 10.0.26100.8875 or later
HOTFIXUpdate Windows 11 Version 26H1 (x64, ARM64) to Build 10.0.28000.2525 or later
Long-term hardening
0/1HARDENINGRestrict physical and remote access to engineering workstations and HMI systems to authorized personnel only
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/d30ce1f2-7498-481f-a44a-68907c43a9a9Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.