Windows Kernel Elevation of Privilege Vulnerability

MonitorCVSS 6.4CVE-2026-62708Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorPhysical
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free vulnerability in the Windows kernel allows an unauthorized attacker with physical access to elevate privileges. Affects Windows Server 2025 and Windows 11 versions 24H2, 25H2, and 26H1 on both x64 and ARM64 architectures. Exploitation requires the ability to execute code at user privilege level on the target system.

What this means
What could happen
An attacker with physical access to a Windows system could exploit a kernel flaw to run commands with elevated privileges, potentially compromising control of the machine.
Who's at risk
IT administrators managing Windows Server 2025, Windows 11 (all recent versions including 24H2, 25H2, and 26H1) on both x64 and ARM64 systems. Relevant to utilities using Windows-based SCADA workstations, HMI systems, or historian servers. Risk is low in typical OT environments due to the physical access requirement.
How it could be exploited
The attacker requires physical access to the system and must trigger a use-after-free condition in the Windows kernel to escalate from user-level code execution to system privileges.
Prerequisites
  • Physical access to the Windows system
  • Ability to execute code at user privilege level
low complexityphysical access requiredaffects privileged operations
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9168
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9168
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9106
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.9168
Windows Server 2025All versionsBuild 10.0.26100.33296
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2704
Windows 11 Version 26H1 for ARM64-based SystemsAll versionsBuild 10.0.28000.2704
Remediation & Mitigation
0/2
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the August 2026 Windows security update to all affected systems
Long-term hardening
0/1
HARDENINGRestrict physical access to servers and workstations to authorized personnel only
API: /api/v1/advisories/0c597f0f-314b-4e17-ba7a-00d2af4a6a7f

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.