Windows Kernel Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-65773Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Improper access control in the Windows Kernel allows a user with valid credentials and local access to elevate their privileges to administrator/SYSTEM level without additional authentication. This vulnerability affects Windows 10 (all versions), Windows 11 (all versions), Windows Server 2019, 2022, and 2025. Microsoft has released patches for all affected product versions.
What this means
What could happen
An attacker with a valid user account on a Windows machine could gain full administrative control of that system, allowing them to install malware, modify critical files, or disrupt operations.
Who's at risk
Water utilities and electric utilities running Windows-based HMIs, engineering workstations, historian servers, or domain controllers on Windows Server 2019, 2022, 2025, Windows 10, or Windows 11 systems. Any environment where non-administrative staff need local or remote access to Windows machines is at risk.
How it could be exploited
An attacker must first obtain legitimate user credentials or access to an unprivileged user account on the Windows system. Once logged in as a regular user, they can execute a specially crafted command or application that exploits the kernel access control flaw to elevate their privileges to SYSTEM/administrator level without requiring additional authentication.
Prerequisites
- Valid user account credentials (unprivileged)
- Local access to the Windows machine or via remote desktop/SSH if enabled
- Ability to execute code or run applications as the authenticated user
Requires valid user credentialsLocal access requiredLow complexity attackAffects all supported Windows versions
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (22)
22 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDDisable unnecessary remote access services (Remote Desktop, SSH) on systems that do not require them
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXApply the August 2026 security update to Windows 10, Windows 11, Windows Server 2019, Windows Server 2022, or Windows Server 2025 as applicable to your environment
Long-term hardening
0/1HARDENINGRestrict user account access—remove standard user accounts that are not necessary and enforce strong password policies to reduce the likelihood of credential compromise
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/388b1dfe-3f55-4210-b8cf-b577523c4262Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.