Windows Kernel Elevation of Privilege Vulnerability
Plan PatchCVSS 7CVE-2026-68884Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
Heap-based buffer overflow in Windows Kernel (CVE-2026-68884) allows an authorized local user to elevate privileges to administrator level. The vulnerability exists in Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025. Microsoft has released fixes in the 2026-Sep security update for all affected versions.
What this means
What could happen
An attacker with a local user account could exploit a buffer overflow in the Windows kernel to gain administrator-level privileges, potentially allowing them to run commands that could disable security controls, install malware, or alter system settings that affect your industrial processes.
Who's at risk
This affects Windows 10 and Windows 11 workstations and Windows Server 2016 through 2025 installations. It should concern IT managers running engineering workstations, HMI servers, data historians, and any Windows-based OT systems. Any machine where an untrusted user might gain a local account is at risk.
How it could be exploited
An attacker must first have a local user account on the Windows system (such as an engineering workstation or HMI). They would then trigger the heap-based buffer overflow in the kernel through a local privilege escalation exploit, gaining System/SYSTEM privileges without further authentication.
Prerequisites
- Local user account on the Windows system
- Local code execution capability (ability to run a program on the machine)
Requires local user account (moderate barrier)Low attack complexity once local access is obtainedCan lead to full system compromiseAffects critical OT systems if Windows hosts are used for process control
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/2
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply Microsoft's 2026-Sep security update to all affected Windows systems (Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2016, 2019, 2022, 2025)
All products
HARDENINGRestrict local administrator access and limit user account privileges to the minimum required for operational duties
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/262777c5-9d8c-4541-ac6d-e5904e21ddbdGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.