Windows Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-69333Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

Use-after-free vulnerability in Windows Win32k kernel subsystem allows a local attacker with user-level privileges to elevate to system-level access. Affects Windows 11 versions 24H2, 25H2, and 26H1 on both x64 and ARM64 architectures.

What this means
What could happen
A user with a regular account on a Windows 11 machine could exploit this flaw to gain full system control. On an OT workstation or engineering PC, this could allow unauthorized modification of control logic, configuration files, or SCADA applications.
Who's at risk
Organizations running Windows 11 on engineering workstations, HMI PCs, or other OT-networked computers should prioritize updates. This affects all current Windows 11 versions (24H2, 25H2, 26H1) on both x64 and ARM64 systems. Focus on machines used for SCADA, PLC programming, or process monitoring.
How it could be exploited
An attacker with a local user account must trigger a specific sequence of Win32k API calls to cause a use-after-free condition in kernel memory. This allows execution of arbitrary code at the highest privilege level (SYSTEM), bypassing normal access controls.
Prerequisites
  • Local user account on the Windows machine
  • Ability to execute code locally (e.g., via an application or script)
  • High complexity exploitation technique required
Requires valid local user accountHigh complexity attackLow exploit probability (0.3% EPSS)Can lead to full system compromiseAffects engineering workstations and HMI machines
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (6)
6 with fix
ProductAffected VersionsFix Status
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.9445
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.9445
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2954
Windows 11 Version 26H1 for ARM64-based SystemsAll versionsBuild 10.0.28000.2954
Remediation & Mitigation
0/5
Schedule — requires maintenance window
0/4

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Windows 11 25H2 systems to Build 10.0.26200.9445 or later
HOTFIXUpdate Windows 11 24H2 systems to Build 10.0.26100.9445 or later
HOTFIXUpdate Windows 11 26H1 systems to Build 10.0.28000.2954 or later
HOTFIXApply the 2026-Sep security update to all affected Windows 11 systems
Long-term hardening
0/1
HARDENINGRestrict physical and network access to Windows 11 machines to trusted users only
API: /api/v1/advisories/c5e1e376-7af9-400b-803d-6c35ce5474c8

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Win32k Elevation of Privilege Vulnerability | CVSS 7 - OTPulse