Windows Kernel Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-62788Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free vulnerability in the Windows kernel allows an authorized local user to elevate privileges. An attacker with user-level access to an affected Windows Server 2025 or Windows 11 system (versions 23H2, 24H2, 25H2, or 26H1) could exploit this to gain administrative control. Microsoft has released kernel updates for all affected builds.

What this means
What could happen
A user with local system access could exploit a memory flaw in the Windows kernel to gain administrative privileges, potentially allowing them to modify system settings, disable security controls, or access sensitive data on the server.
Who's at risk
Water utilities and electric utilities operating on Windows Server 2025 or Windows 11 systems (versions 23H2, 24H2, 25H2, or 26H1 on x64 or ARM64 platforms). This affects both standalone servers and servers deployed in SCADA or industrial process environments where Windows provides supervisory control or data acquisition functions.
How it could be exploited
An attacker with a user account on the system (such as a remote desktop user or local service account) could trigger a use-after-free condition in the kernel to elevate their privileges to system/administrator level. This requires local code execution; the attacker cannot exploit it directly from the network.
Prerequisites
  • Local user account with login access to the Windows system
  • Ability to execute code on the system with user-level privileges
Requires local access (not remotely exploitable from the network)Requires valid user credentialsModerately complex attack (high AC rating)Affects availability, confidentiality, and integrity
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (10)
10 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9168
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9168
Windows 11 Version 23H2 for ARM64-based SystemsAll versionsBuild 10.0.22631.7517
Windows 11 Version 23H2 for x64-based SystemsAll versionsBuild 10.0.22631.7517
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9106
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.9168
Windows Server 2025All versionsBuild 10.0.26100.33296
Remediation & Mitigation
0/2
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Aug Windows security update to all affected Windows Server and Windows 11 systems
Long-term hardening
0/1
HARDENINGRestrict local system access to only trusted administrator and service accounts; audit and remove unnecessary user accounts
API: /api/v1/advisories/b12a844b-397b-4510-842b-188288fc17c1

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.