Windows Kerberos Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-62754Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
What this means
What could happen
A local user with standard credentials could exploit this to gain administrative privileges on a Windows system, potentially allowing them to modify industrial control software, alter system settings, or disable security controls.
Who's at risk
Windows administrators and OT teams managing Windows servers or workstations in industrial environments, particularly those running Windows Server 2016, 2019, 2022, or 2025 for data collection, HMI systems, or engineering workstations that host or support industrial control software.
How it could be exploited
An attacker with a local user account on a Windows machine triggers a heap buffer overflow in Kerberos processing. This allows the attacker to execute code with SYSTEM privileges, escalating from their original user-level access.
Prerequisites
- Local user account on the Windows system
- Standard (non-administrator) credentials required
- Local code execution capability (ability to run commands on the machine)
Privilege escalation possible with local accessAffects multiple Windows versionsRequires local authenticationLow complexity attack
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (24)
24 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/2HARDENINGRestrict local user account creation and login on critical OT Windows systems to authorized personnel only
HARDENINGImplement local account logon restrictions on Windows systems running industrial software to prevent unauthorized interactive access
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXPrioritize patching Windows Server 2019, 2022, and 2025 installations in your OT network
All products
HOTFIXApply the August 2026 Windows security update for your Windows OS version
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/014f08e7-f60c-49fa-a6c9-7f847cab7b73Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.