Windows Kernel Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-58532Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Integer overflow or wraparound in the Windows Kernel allows an authorized local attacker to escalate privileges. Exploitation is assessed as less likely. All supported Windows 10, Windows 11, and Windows Server versions (2016 through 2025) are affected. Microsoft has released patches for all affected platforms in the 2026-Jul security update.
What this means
What could happen
An attacker with a local user account on a Windows PC or server could exploit an integer overflow in the kernel to gain administrator privileges, allowing them to install malware, modify system configurations, or interfere with critical services running on that machine.
Who's at risk
Windows 10 and Windows 11 systems (all supported versions), Windows Server 2016, 2019, 2022, and 2025 installations. This affects IT staff, SCADA workstations, historian servers, engineering stations, and any Windows systems used for OT monitoring or control in water, electric, and other critical infrastructure environments.
How it could be exploited
An attacker with a standard user account runs a malicious program on the affected Windows system. The program exploits an integer overflow vulnerability in the Windows kernel to escalate privileges from user to administrator level. Once elevated, the attacker can execute any command on the system.
Prerequisites
- Local user account or equivalent logon capability on the affected Windows system
- Ability to execute programs (e.g., run a crafted executable or script)
Low complexity exploitationRequires local access (not remotely exploitable)Affects Windows Servers used for critical operations
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the 2026-Jul Windows security update for your Windows version (see product fixes for specific build numbers)
Long-term hardening
0/2HARDENINGRestrict local administrative access and limit user account privileges to the minimum required for operations
HARDENINGMonitor and audit local logon activity on critical systems for unusual user accounts or failed logon attempts
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/31bc1d01-2fd5-45d8-998e-5427af796559Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.