Windows Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-62712Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Heap-based buffer overflow in Windows Win32K kernel subsystem allows a standard user with local access to elevate privileges to administrator level. A specially crafted application can trigger the overflow and write to kernel memory without requiring user interaction after execution. The vulnerability affects Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures.

What this means
What could happen
An attacker with a standard user account on a Windows system could run commands with administrator privileges, allowing them to modify system settings, install software, alter critical configurations, or disable security controls on HMI workstations or engineering computers in your facility.
Who's at risk
This affects Windows-based engineering workstations, HMI systems, historian servers, and any Windows Server systems used in industrial automation environments. Any facility using Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 is affected, regardless of system role.
How it could be exploited
An attacker with local user credentials could run a specially crafted application that triggers a heap buffer overflow in the Win32k kernel subsystem. This overflow allows the attacker to write to kernel memory and escalate their privileges to administrator/system level without further user interaction.
Prerequisites
  • Local user account with standard (non-administrator) privileges
  • Ability to execute applications on the Windows system
Remotely exploitable via subsequent compromise (attacker must first gain local access)Low complexity attackHigh CVSS score (7.8)Exploitation more likely per Microsoft
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Remediation & Mitigation
0/2
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply Microsoft August 2026 security update to all affected Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems
Windows Server 2019
HOTFIXVerify patched systems are running required build numbers before returning to production (Windows 10 1809: 17763.9115+, Windows 10 21H2: 19044.7663+, Windows 10 22H2: 19045.7663+, Windows 11 23H2: 22631.7517+, Windows 11 24H2/25H2: 26100.9168+ or later, Windows Server 2016: 14393.9418+, Windows Server 2019: 17763.9115+, Windows Server 2022: 20348.5499+, Windows Server 2025: 26100.33296+)
API: /api/v1/advisories/19a7db58-8e07-4df4-9543-f36fe19bbe67

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Win32k Elevation of Privilege Vulnerability | CVSS 7.8 - OTPulse