Windows Win32k Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-62712Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Heap-based buffer overflow in Windows Win32K kernel subsystem allows a standard user with local access to elevate privileges to administrator level. A specially crafted application can trigger the overflow and write to kernel memory without requiring user interaction after execution. The vulnerability affects Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures.
What this means
What could happen
An attacker with a standard user account on a Windows system could run commands with administrator privileges, allowing them to modify system settings, install software, alter critical configurations, or disable security controls on HMI workstations or engineering computers in your facility.
Who's at risk
This affects Windows-based engineering workstations, HMI systems, historian servers, and any Windows Server systems used in industrial automation environments. Any facility using Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 is affected, regardless of system role.
How it could be exploited
An attacker with local user credentials could run a specially crafted application that triggers a heap buffer overflow in the Win32k kernel subsystem. This overflow allows the attacker to write to kernel memory and escalate their privileges to administrator/system level without further user interaction.
Prerequisites
- Local user account with standard (non-administrator) privileges
- Ability to execute applications on the Windows system
Remotely exploitable via subsequent compromise (attacker must first gain local access)Low complexity attackHigh CVSS score (7.8)Exploitation more likely per Microsoft
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/2
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply Microsoft August 2026 security update to all affected Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems
Windows Server 2019
HOTFIXVerify patched systems are running required build numbers before returning to production (Windows 10 1809: 17763.9115+, Windows 10 21H2: 19044.7663+, Windows 10 22H2: 19045.7663+, Windows 11 23H2: 22631.7517+, Windows 11 24H2/25H2: 26100.9168+ or later, Windows Server 2016: 14393.9418+, Windows Server 2019: 17763.9115+, Windows Server 2022: 20348.5499+, Windows Server 2025: 26100.33296+)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/19a7db58-8e07-4df4-9543-f36fe19bbe67Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.