Windows Win32k Elevation of Privilege Vulnerability
Plan PatchCVSS 7CVE-2026-69333Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
Use-after-free vulnerability in Windows Win32k kernel subsystem allows a local attacker with user-level privileges to elevate to system-level access. Affects Windows 11 versions 24H2, 25H2, and 26H1 on both x64 and ARM64 architectures.
What this means
What could happen
A user with a regular account on a Windows 11 machine could exploit this flaw to gain full system control. On an OT workstation or engineering PC, this could allow unauthorized modification of control logic, configuration files, or SCADA applications.
Who's at risk
Organizations running Windows 11 on engineering workstations, HMI PCs, or other OT-networked computers should prioritize updates. This affects all current Windows 11 versions (24H2, 25H2, 26H1) on both x64 and ARM64 systems. Focus on machines used for SCADA, PLC programming, or process monitoring.
How it could be exploited
An attacker with a local user account must trigger a specific sequence of Win32k API calls to cause a use-after-free condition in kernel memory. This allows execution of arbitrary code at the highest privilege level (SYSTEM), bypassing normal access controls.
Prerequisites
- Local user account on the Windows machine
- Ability to execute code locally (e.g., via an application or script)
- High complexity exploitation technique required
Requires valid local user accountHigh complexity attackLow exploit probability (0.3% EPSS)Can lead to full system compromiseAffects engineering workstations and HMI machines
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (6)
6 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/5
Schedule — requires maintenance window
0/4Patching may require device reboot — plan for process interruption
HOTFIXUpdate Windows 11 25H2 systems to Build 10.0.26200.9445 or later
HOTFIXUpdate Windows 11 24H2 systems to Build 10.0.26100.9445 or later
HOTFIXUpdate Windows 11 26H1 systems to Build 10.0.28000.2954 or later
HOTFIXApply the 2026-Sep security update to all affected Windows 11 systems
Long-term hardening
0/1HARDENINGRestrict physical and network access to Windows 11 machines to trusted users only
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/c5e1e376-7af9-400b-803d-6c35ce5474c8Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.