Windows Win32k Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-65775Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A use-after-free vulnerability in Windows Win32K kernel graphics subsystem allows an authorized user to escalate privileges locally to SYSTEM level. The flaw affects Windows 10 (all versions from 1607 to 22H2), Windows 11 (all versions), Windows Server 2016, 2019, 2022, and 2025. An attacker with user-level code execution can trigger the condition to gain administrative access without additional authentication.
What this means
What could happen
An attacker with local access to a Windows workstation or server could exploit this flaw to gain system-level privileges, allowing them to install malware, modify control systems software, or disrupt operations.
Who's at risk
Windows IT managers and plant floor personnel who use Windows 10 or Windows Server 2016–2025 machines for SCADA workstations, engineering workstations, historians, or operator consoles. Any OT environment where HMI software, control system engineering tools, or data collection runs on Windows.
How it could be exploited
An attacker who already has a user account on a Windows machine (or can gain one through phishing or another method) can trigger a use-after-free condition in the Windows kernel graphics subsystem to escalate from user privileges to administrator/SYSTEM level, giving them full control of the machine.
Prerequisites
- Local user account (or ability to execute code as a standard user on the target system)
- Physical or remote access to run code (e.g., via compromised application or RDP session)
- Unpatched Windows 10 or Windows Server 2016-2025
Affects all Windows desktop and server versions (10, 11, Server 2016-2025)Requires local access but no special tools or complexityCould lead to full system compromise of engineering or operator workstations
Exploitability
Some exploitation risk — EPSS score 2.6%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the August 2026 Microsoft security update to bring Windows systems to the patched build versions listed in the advisory
Long-term hardening
0/3HARDENINGRestrict local user account access on Windows servers and workstations to only necessary personnel
HARDENINGEnable Windows Defender Application Guard or User Access Control (UAC) enforcement to limit user-to-system privilege escalation vectors
HARDENINGMonitor Windows event logs for unexpected privilege escalation attempts (Event IDs 4720, 4722, 4728, 4732, 4756)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/f25fa2fd-4fcc-4603-8349-317b86b38358Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.