Windows Kernel Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-62780Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free vulnerability in the Windows Kernel allows an authorized local user to escalate privileges to administrator level on affected Windows Server 2025 and Windows 11 systems (versions 23H2, 24H2, 25H2, 26H1). The vulnerability requires local system access but does not require additional authentication bypass. Microsoft has released patches via August 2026 security updates for all affected versions.

What this means
What could happen
An attacker with local access to a Windows system could gain elevated privileges, potentially allowing them to disable security controls, modify PLC or SCADA communications, or shut down critical services running on that system.
Who's at risk
Organizations running Windows Server 2025 or Windows 11 (any supported version) should prioritize systems in the OT environment, especially: engineering workstations that control or monitor PLCs and SCADA systems, data historian servers that aggregate process data, HMI (Human-Machine Interface) host machines, and any Windows system with administrative credentials for industrial equipment.
How it could be exploited
An attacker with a local user account on a Windows workstation or server could trigger a use-after-free condition in the Windows Kernel to escalate privileges from standard user to administrator/system level. This could be chained with network access to downstream OT devices if the compromised Windows system has administrative access to control systems or data historians.
Prerequisites
  • Local user account on the affected Windows system
  • Interactive or network logon access to trigger the kernel condition
Affects Windows Server (OT backbone systems)Requires local access but no authentication circumvention neededEscalates user privileges to administrator levelLow exploitation likelihood but high impact if achieved
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (10)
10 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9168
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9168
Windows 11 Version 23H2 for ARM64-based SystemsAll versionsBuild 10.0.22631.7517
Windows 11 Version 23H2 for x64-based SystemsAll versionsBuild 10.0.22631.7517
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9106
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.9168
Windows Server 2025All versionsBuild 10.0.26100.33296
Remediation & Mitigation
0/2
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Windows Server 2025
HOTFIXApply Windows security updates from August 2026 or later to all affected Windows Server 2025, Windows 11 23H2, 24H2, 25H2, and 26H1 systems
All products
HOTFIXPrioritize patching Windows systems that have direct or network-bridged access to OT networks (SCADA servers, historians, engineering workstations, HMI hosts)
API: /api/v1/advisories/5424f6f7-f199-46da-a476-5ddb5141b72a

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.