Windows Win32k Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-62885Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A heap-based buffer overflow in Windows Win32K driver allows an authorized local user to elevate privileges to administrative level. The vulnerability exists in Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025. Microsoft has released patches for all affected versions.
What this means
What could happen
A user with local access to a Windows computer or server could exploit this buffer overflow vulnerability to gain administrative privileges and take full control of the system. In an OT environment, this means an attacker with physical or local network access could modify control logic, disable safety systems, or shut down critical processes.
Who's at risk
This affects any organization running Windows 10, Windows 11, or Windows Server 2016–2025 systems that interact with OT networks. This includes engineering workstations, HMI (human-machine interface) servers, data historians, remote access jump hosts, and any Windows-based control system frontend. Water authorities and utilities using Windows for SCADA monitoring or plant management are affected.
How it could be exploited
An attacker must already have local user-level access to the Windows system (via RDP, physical access, or a compromised low-privilege account). They would trigger a heap-based buffer overflow in the Win32K driver through a specially crafted request, causing a crash that yields administrative-level code execution. This could then be used to modify HMI applications, PLCs, or historical data systems.
Prerequisites
- Local user account on the Windows system (no admin rights required)
- Ability to execute code or run an application on the target Windows machine
Local privilege escalation (requires initial user access)Low complexity attackAffects control system access points (HMI/workstations)Vendor patches available for all versions
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXUpdate Windows systems to the August 2026 security patch or later
HOTFIXApply Microsoft security updates during your next scheduled maintenance window
Long-term hardening
0/1HARDENINGReview user access logs to detect any unauthorized local logon attempts or privilege escalation activity
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/3faa03eb-65c5-4ca6-a682-7abe5a502a1eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.