Windows Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 8CVE-2026-69301Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary

Stack-based buffer overflow in Windows Win32k kernel driver allows an authorized attacker to elevate privileges. Affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 (all editions).

What this means
What could happen
An attacker with a valid user account could exploit this to run commands with system privileges, potentially gaining full control of the device and any connected OT/IT networks.
Who's at risk
Windows IT administrators responsible for servers, workstations, and HMI (human-machine interface) devices running Windows in water or electric utilities. Specific concern: engineering workstations, control system servers, and any Windows-based industrial equipment with network access.
How it could be exploited
An attacker with valid login credentials on a Windows device uses a specially crafted Win32k API call to trigger the buffer overflow. This allows privilege escalation from user to system level without further authentication, enabling access to sensitive device functions and data.
Prerequisites
  • Valid user account credentials on the target Windows device
  • Local or remote network access to the device
  • Ability to execute code or send API calls on the device
No authentication required after initial loginLow complexity to exploitHigh privilege impactAffects multiple critical Windows versions widely deployed in utilities
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/4
Do now
0/1
HARDENINGRestrict login access to critical Windows devices to authorized personnel only; use strong credentials and multi-factor authentication where available
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXInstall the September 2026 security update for your Windows version (see fixed version for your build below)
HOTFIXPrioritize patching Windows devices used for OT/control system access and administrative functions
Long-term hardening
0/1
HARDENINGSegment network access so that compromised user accounts cannot directly reach critical OT systems or servers
API: /api/v1/advisories/d5249e72-cef4-4234-a704-2a779ce7718c

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.