Windows Kernel Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-62737Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A Windows kernel vulnerability (untrusted pointer dereference) allows an authorized local user to elevate privileges to administrator level. The vulnerability affects Windows Server 2025 and all current versions of Windows 11 across x64 and ARM64 architectures. Microsoft has released patches via the 2026-August security update.
What this means
What could happen
An attacker with a user account on the system could exploit this kernel vulnerability to gain administrative privileges, potentially allowing them to install malware, modify system configurations, or interfere with OT applications running on the server.
Who's at risk
Windows Server 2025 and Windows 11 (all versions including 24H2, 25H2, and 26H1 for both x64 and ARM64 architectures). This affects any OT engineering workstations or control servers running these operating systems, particularly those used for HMI, data historians, or support systems.
How it could be exploited
An attacker must first obtain a local user account on the affected Windows system. Once authenticated, they can trigger an untrusted pointer dereference in the Windows kernel to escalate privileges from user-level to administrator/system-level. This direct local attack requires no network traversal but assumes prior account compromise.
Prerequisites
- Valid user account on the affected Windows system
- Local system access (interactive or remote desktop session)
Low attack complexityRequires valid user credentialsHigh EPSS score (exploitation more likely)Could lead to full system compromise
Exploitability
Some exploitation risk — EPSS score 2.8%
Public Proof-of-Concept (PoC) on GitHub (2 repositories)
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2025
HOTFIXInstall the 2026-August Windows security update for your version of Windows Server 2025, Windows 11 (all versions and architectures)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/c68ad25b-cdf2-42cc-a6ba-4d393fee8b21Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.