Windows Kernel Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-61930Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A heap-based buffer overflow vulnerability in the Windows Kernel allows an authorized local attacker to escalate privileges to administrator or system level. The vulnerability affects Windows 10 (all versions), Windows 11 (all versions), Windows Server 2016, 2019, 2022, and 2025. Exploitation is assessed as more likely and requires local user account access and the ability to execute a specially crafted application.
What this means
What could happen
An attacker with a local user account on a Windows computer or server could exploit this buffer overflow to gain administrator or system-level privileges, potentially allowing them to install malware, modify critical files, or disrupt operations on systems running SCADA or ICS software.
Who's at risk
All organizations running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 systems are affected. This is particularly critical for water utilities and electric systems using Windows-based HMI (Human-Machine Interface) computers, engineering workstations, or servers that run ICS software or communicate with field devices.
How it could be exploited
An attacker with local user access runs a specially crafted application that triggers a heap-based buffer overflow in the Windows Kernel. The overflow overwrites kernel memory, allowing the attacker to escalate privileges to administrator or system level without requiring administrative credentials or user interaction.
Prerequisites
- Local user account access on the target Windows system
- Ability to execute applications or scripts on the system
Low complexity exploitRequires local access (not remotely exploitable)Affects widely deployed operating systemsHigh impact if successful on critical control systems
Exploitability
Some exploitation risk — EPSS score 2.1%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1HARDENINGRestrict local system access to trusted users only; review and remove unnecessary local user accounts
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply the August 2026 Windows security update to all affected Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems
Long-term hardening
0/1HARDENINGMonitor system logs and audit trails for failed privilege escalation attempts
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/fec9313c-7946-4968-bfc5-4bd485d41929Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.