Windows Kerberos Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-62752Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally on affected Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems.

What this means
What could happen
A user with local access to a Windows system could exploit this vulnerability to gain administrator-level privileges, potentially allowing them to modify system configurations, access sensitive data, or interfere with critical services running on that machine.
Who's at risk
IT operations and system administrators managing Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 systems in any sector (water utilities, electric utilities, manufacturing, etc.). This affects both standard workstations and server-class systems, including Server Core installations. Any system with local user access and these Windows versions is at risk.
How it could be exploited
An attacker with a standard user account on an affected Windows system can trigger a heap buffer overflow in the Kerberos authentication component through a specially crafted local request, causing a memory corruption that results in privilege escalation to SYSTEM or administrator level.
Prerequisites
  • Local user account on affected Windows system
  • No special privileges or credentials required to trigger the vulnerability
Low complexity exploitationAffects multiple Windows versions and Server editionsDefault configurations vulnerable
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Remediation & Mitigation
0/12
Schedule — requires maintenance window
0/12

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply August 2026 security update to Windows Server 2016 (Build 10.0.14393.9418 or later)
Windows Server 2019
HOTFIXApply August 2026 security update to Windows Server 2019 (Build 10.0.17763.9115 or later)
Windows Server 2022
HOTFIXApply August 2026 security update to Windows Server 2022 (Build 10.0.20348.5499 or later)
Windows Server 2025
HOTFIXApply August 2026 security update to Windows Server 2025 (Build 10.0.26100.33296 or later)
All products
HOTFIXApply August 2026 security update to Windows 10 Version 1607 (Build 10.0.14393.9418 or later)
HOTFIXApply August 2026 security update to Windows 10 Version 1809 (Build 10.0.17763.9115 or later)
HOTFIXApply August 2026 security update to Windows 10 Version 21H2 (Build 10.0.19044.7663 or later)
HOTFIXApply August 2026 security update to Windows 10 Version 22H2 (Build 10.0.19045.7663 or later)
HOTFIXApply August 2026 security update to Windows 11 Version 23H2 (Build 10.0.22631.7517 or later)
HOTFIXApply August 2026 security update to Windows 11 Version 24H2 (Build 10.0.26200.9106 or later)
HOTFIXApply August 2026 security update to Windows 11 Version 25H2 (Build 10.0.26200.9168 or later)
HOTFIXApply August 2026 security update to Windows 11 Version 26H1 (Build 10.0.28000.2704 or later)
API: /api/v1/advisories/e5eab2b2-ec7d-4ca2-8e3f-aa0db99f29b7

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.