Windows Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-69335Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free memory vulnerability in Windows Win32k kernel component allows an authorized local user to elevate privileges. An attacker with a local user account can execute a specially crafted program to bypass privilege checks and gain system-level access, enabling unauthorized control or modification of the affected system.

What this means
What could happen
A user with local access to a Windows computer or server could run a specially crafted program to gain administrator-level control, potentially allowing them to modify industrial software, access sensitive data, or disrupt operations.
Who's at risk
IT managers and operators at utilities and water authorities running Windows on engineering workstations, HMI (human-machine interface) systems, historian servers, or domain controllers should prioritize patching. This includes Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 environments used for monitoring and controlling industrial equipment.
How it could be exploited
An attacker with a local user account executes a specially crafted program that exploits a use-after-free memory flaw in the Win32k kernel component. This allows the attacker to bypass privilege checks and execute code with system privileges, gaining full control of the computer.
Prerequisites
  • Local user account access to the affected Windows system
  • Ability to execute arbitrary programs on the system
Requires local user accessModerate complexity attackAffects integrity and confidentiality of systemPrivilege escalation vector
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply the September 2026 Windows security update (or later) to all affected Windows 10, Windows 11, Windows Server 2016, Server 2019, Server 2022, and Server 2025 systems.
API: /api/v1/advisories/76014604-545b-401d-bc71-89746a6bc6d8

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Win32k Elevation of Privilege Vulnerability | CVSS 7 - OTPulse