Windows Kerberos Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-62773Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

Use after free vulnerability in Windows Kerberos allows an authorized local attacker to elevate privileges. The vulnerability exists in memory management of Kerberos authentication components and can be exploited by a user with local access to run code at a higher privilege level.

What this means
What could happen
A user with a local account on a domain-joined Windows server or workstation could elevate their privileges to run commands as an administrator or system account, potentially allowing them to modify control system configurations, disable security controls, or interfere with critical operations.
Who's at risk
Windows systems used in OT environments, including engineering workstations, historian servers, and domain controllers integrated into control networks. Particularly relevant for utilities running Windows Server 2016/2019/2022 in SCADA, HMI, or data acquisition roles where domain authentication is used.
How it could be exploited
An attacker with a valid local user account on a domain-joined Windows system triggers the use-after-free vulnerability through Kerberos authentication operations, causing memory corruption that allows arbitrary code execution at elevated privilege levels.
Prerequisites
  • Valid local user account on a domain-joined Windows system
  • Local console or RDP access to the affected system
Locally exploitableRequires valid credentialsAffects domain-joined systemsHigher complexity exploitation
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Remediation & Mitigation
0/2
Do now
0/1
WORKAROUNDIf immediate patching is not possible, restrict local account access to servers running Kerberos authentication—limit RDP/console access to only necessary administrative staff and monitor for suspicious privilege escalation attempts.
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXInstall the 2026-Aug security update for your Windows version. For Windows 10/11, update to the specified build number listed for your version. For Windows Server 2016/2019/2022/2025, apply the corresponding security update build.
API: /api/v1/advisories/9a886bf2-09eb-447d-ad77-e229539948da

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.