Windows Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-62711Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Use after free vulnerability in Windows Win32k kernel driver allows a local authenticated attacker to elevate privileges to administrator level. Affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures. Exploitation is assessed as less likely, but successful exploitation grants full system compromise.

What this means
What could happen
A local attacker with user-level access can exploit a flaw in Windows graphics handling to gain full system (administrator) privileges on the affected machine. This could allow them to install malware, steal data, or sabotage operations.
Who's at risk
Organizations running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 on engineering workstations, HMI/SCADA workstations, or any administrative systems used to manage industrial equipment. This is a particular concern for any workstation that accesses PLCs, RTUs, or other control systems, as a compromised workstation could be used as a springboard to attack the operational network.
How it could be exploited
An attacker with a user account on the Windows machine can trigger a use-after-free condition in the Win32k kernel driver by making specially crafted graphics API calls. The kernel memory corruption allows the attacker to overwrite privilege tokens or execute arbitrary code with administrator rights.
Prerequisites
  • Valid user account on the Windows system (local access required)
  • No additional privileges needed for initial access
  • No special configuration or service dependencies
Local privilege escalationLow complexity exploitDefault/standard Windows installation at riskAffects administrative and engineering workstations
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply Windows security updates: Build 10.0.17763.9115 for Windows 10 1809 and Server 2019; Build 10.0.20348.5499 for Server 2022; Build 10.0.19044.7663 for Windows 10 21H2; Build 10.0.19045.7663 for Windows 10 22H2; Build 10.0.26200.9168 for Windows 11 25H2; Build 10.0.22631.7517 for Windows 11 23H2; Build 10.0.26100.9168 for Windows 11 24H2; Build 10.0.28000.2704 for Windows 11 26H1; Build 10.0.14393.9418 for Windows 10 1607 and Server 2016; Build 10.0.26100.33296 for Server 2025
API: /api/v1/advisories/a429809f-5010-473c-87ec-08986682a690

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Win32k Elevation of Privilege Vulnerability | CVSS 7.8 - OTPulse