Windows Win32k Elevation of Privilege Vulnerability
Plan PatchCVSS 7CVE-2026-65776Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
A use-after-free vulnerability in Windows Win32K allows an authorized local user to elevate their privileges on Windows Server 2025, Windows 11 (versions 24H2, 25H2, and 26H1) on both x64 and ARM64 systems.
What this means
What could happen
An attacker with a local user account could gain system-level access to Windows servers or workstations, potentially allowing them to modify control logic, disable monitoring, or compromise the entire system.
Who's at risk
Windows Server 2025 (both full and Server Core installations) and Windows 11 workstations (versions 24H2, 25H2, and 26H1) running on x64 and ARM64 architectures. This affects IT operations servers, engineering workstations, and any Windows-based HMI or historian systems in your facility.
How it could be exploited
An attacker must first have local user access to the system (via compromised account, insider access, or prior exploitation). They then exploit the Win32K vulnerability to escalate from user privileges to system privileges, gaining full control of the machine.
Prerequisites
- Local user account credentials (non-admin)
- Interactive access to the target Windows system
- User must be able to execute code in the Win32K context
Local privilege escalation requiredRequires valid local user credentialsAffects critical server operating systemsMedium complexity exploitation
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/7
Schedule — requires maintenance window
0/6Patching may require device reboot — plan for process interruption
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33296 or later
All products
HOTFIXUpdate Windows 11 Version 25H2 (x64) to Build 10.0.26200.9168 or later
HOTFIXUpdate Windows 11 Version 25H2 (ARM64) to Build 10.0.26200.9168 or later
HOTFIXUpdate Windows 11 Version 24H2 (x64) to Build 10.0.26100.9168 or later
HOTFIXUpdate Windows 11 Version 24H2 (ARM64) to Build 10.0.26200.9106 or later
HOTFIXUpdate Windows 11 Version 26H1 (x64 and ARM64) to Build 10.0.28000.2704 or later
Long-term hardening
0/1HARDENINGReview and restrict local administrative account access on critical servers
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/1f003a5a-04d7-4795-a950-8519a36da395Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.