Windows Kernel Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-62737Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A Windows kernel vulnerability (untrusted pointer dereference) allows an authorized local user to elevate privileges to administrator level. The vulnerability affects Windows Server 2025 and all current versions of Windows 11 across x64 and ARM64 architectures. Microsoft has released patches via the 2026-August security update.

What this means
What could happen
An attacker with a user account on the system could exploit this kernel vulnerability to gain administrative privileges, potentially allowing them to install malware, modify system configurations, or interfere with OT applications running on the server.
Who's at risk
Windows Server 2025 and Windows 11 (all versions including 24H2, 25H2, and 26H1 for both x64 and ARM64 architectures). This affects any OT engineering workstations or control servers running these operating systems, particularly those used for HMI, data historians, or support systems.
How it could be exploited
An attacker must first obtain a local user account on the affected Windows system. Once authenticated, they can trigger an untrusted pointer dereference in the Windows kernel to escalate privileges from user-level to administrator/system-level. This direct local attack requires no network traversal but assumes prior account compromise.
Prerequisites
  • Valid user account on the affected Windows system
  • Local system access (interactive or remote desktop session)
Low attack complexityRequires valid user credentialsHigh EPSS score (exploitation more likely)Could lead to full system compromise
Exploitability
Some exploitation risk — EPSS score 2.8%
Public Proof-of-Concept (PoC) on GitHub (2 repositories)
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9168
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9168
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.9106
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.9168
Windows Server 2025All versionsBuild 10.0.26100.33296
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2704
Windows 11 Version 26H1 for ARM64-based SystemsAll versionsBuild 10.0.28000.2704
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2025
HOTFIXInstall the 2026-August Windows security update for your version of Windows Server 2025, Windows 11 (all versions and architectures)
API: /api/v1/advisories/c68ad25b-cdf2-42cc-a6ba-4d393fee8b21

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Kernel Elevation of Privilege Vulnerability | CVSS 7.8 - OTPulse