Windows Win32k Elevation of Privilege Vulnerability
Plan PatchCVSS 7CVE-2026-69335Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
A use-after-free memory vulnerability in Windows Win32k kernel component allows an authorized local user to elevate privileges. An attacker with a local user account can execute a specially crafted program to bypass privilege checks and gain system-level access, enabling unauthorized control or modification of the affected system.
What this means
What could happen
A user with local access to a Windows computer or server could run a specially crafted program to gain administrator-level control, potentially allowing them to modify industrial software, access sensitive data, or disrupt operations.
Who's at risk
IT managers and operators at utilities and water authorities running Windows on engineering workstations, HMI (human-machine interface) systems, historian servers, or domain controllers should prioritize patching. This includes Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 environments used for monitoring and controlling industrial equipment.
How it could be exploited
An attacker with a local user account executes a specially crafted program that exploits a use-after-free memory flaw in the Win32k kernel component. This allows the attacker to bypass privilege checks and execute code with system privileges, gaining full control of the computer.
Prerequisites
- Local user account access to the affected Windows system
- Ability to execute arbitrary programs on the system
Requires local user accessModerate complexity attackAffects integrity and confidentiality of systemPrivilege escalation vector
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply the September 2026 Windows security update (or later) to all affected Windows 10, Windows 11, Windows Server 2016, Server 2019, Server 2022, and Server 2025 systems.
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/76014604-545b-401d-bc71-89746a6bc6d8Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.