Windows Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-65776Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free vulnerability in Windows Win32K allows an authorized local user to elevate their privileges on Windows Server 2025, Windows 11 (versions 24H2, 25H2, and 26H1) on both x64 and ARM64 systems.

What this means
What could happen
An attacker with a local user account could gain system-level access to Windows servers or workstations, potentially allowing them to modify control logic, disable monitoring, or compromise the entire system.
Who's at risk
Windows Server 2025 (both full and Server Core installations) and Windows 11 workstations (versions 24H2, 25H2, and 26H1) running on x64 and ARM64 architectures. This affects IT operations servers, engineering workstations, and any Windows-based HMI or historian systems in your facility.
How it could be exploited
An attacker must first have local user access to the system (via compromised account, insider access, or prior exploitation). They then exploit the Win32K vulnerability to escalate from user privileges to system privileges, gaining full control of the machine.
Prerequisites
  • Local user account credentials (non-admin)
  • Interactive access to the target Windows system
  • User must be able to execute code in the Win32K context
Local privilege escalation requiredRequires valid local user credentialsAffects critical server operating systemsMedium complexity exploitation
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33296
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9168
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9168
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9106
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.9168
Windows Server 2025All versionsBuild 10.0.26100.33296
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2704
Windows 11 Version 26H1 for ARM64-based SystemsAll versionsBuild 10.0.28000.2704
Remediation & Mitigation
0/7
Schedule — requires maintenance window
0/6

Patching may require device reboot — plan for process interruption

Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33296 or later
All products
HOTFIXUpdate Windows 11 Version 25H2 (x64) to Build 10.0.26200.9168 or later
HOTFIXUpdate Windows 11 Version 25H2 (ARM64) to Build 10.0.26200.9168 or later
HOTFIXUpdate Windows 11 Version 24H2 (x64) to Build 10.0.26100.9168 or later
HOTFIXUpdate Windows 11 Version 24H2 (ARM64) to Build 10.0.26200.9106 or later
HOTFIXUpdate Windows 11 Version 26H1 (x64 and ARM64) to Build 10.0.28000.2704 or later
Long-term hardening
0/1
HARDENINGReview and restrict local administrative account access on critical servers
API: /api/v1/advisories/1f003a5a-04d7-4795-a950-8519a36da395

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.