Windows Kernel Elevation of Privilege Vulnerability
MonitorCVSS 6.4CVE-2026-62708Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorPhysical
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary
A use-after-free vulnerability in the Windows kernel allows an unauthorized attacker with physical access to elevate privileges. Affects Windows Server 2025 and Windows 11 versions 24H2, 25H2, and 26H1 on both x64 and ARM64 architectures. Exploitation requires the ability to execute code at user privilege level on the target system.
What this means
What could happen
An attacker with physical access to a Windows system could exploit a kernel flaw to run commands with elevated privileges, potentially compromising control of the machine.
Who's at risk
IT administrators managing Windows Server 2025, Windows 11 (all recent versions including 24H2, 25H2, and 26H1) on both x64 and ARM64 systems. Relevant to utilities using Windows-based SCADA workstations, HMI systems, or historian servers. Risk is low in typical OT environments due to the physical access requirement.
How it could be exploited
The attacker requires physical access to the system and must trigger a use-after-free condition in the Windows kernel to escalate from user-level code execution to system privileges.
Prerequisites
- Physical access to the Windows system
- Ability to execute code at user privilege level
low complexityphysical access requiredaffects privileged operations
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/2
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the August 2026 Windows security update to all affected systems
Long-term hardening
0/1HARDENINGRestrict physical access to servers and workstations to authorized personnel only
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/0c597f0f-314b-4e17-ba7a-00d2af4a6a7fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.