Windows Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-69348Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A heap-based buffer overflow in Windows Win32K allows a local user without administrator privileges to elevate to SYSTEM-level access. The vulnerability affects Windows Server 2025 and Windows 11 (versions 24H2, 25H2, and 26H1) on both x64 and ARM64 architectures. Microsoft rates exploitation as less likely and recommends applying the 2026-Sep security update.

What this means
What could happen
A user with local access to a Windows system can exploit a heap buffer overflow in Win32K to gain system-level privileges, potentially allowing them to modify industrial control logic, disable safety systems, or disrupt critical operations on any Windows-based HMI or engineering workstation on your network.
Who's at risk
Water and electric utilities operating Windows-based HMI systems, SCADA servers, data historians, and engineering workstations. This affects any plant control room or remote monitoring system running Windows Server 2025 or Windows 11, particularly systems that permit multiple local user accounts or allow remote desktop access from corporate networks.
How it could be exploited
An attacker with a local user account on a Windows Server or Windows 11 system sends a specially crafted input to the Win32K kernel component. The heap buffer overflow allows the attacker to execute arbitrary code with SYSTEM privileges without needing administrator credentials beforehand. On an ICS network, this could target HMI systems, data historians, or engineering workstations that have local user accounts.
Prerequisites
  • Local user account on the affected Windows system
  • Physical or remote desktop access to the system
  • No administrator credentials required
Low complexity exploitationLow EPSS score (0.3%)Requires local user account (not remotely exploitable directly)Affects Windows Server and workstations used for ICS management
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.9445
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.9445
Windows Server 2025All versionsBuild 10.0.26100.33438
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2954
Windows 11 Version 26H1 for ARM64-based SystemsAll versionsBuild 10.0.28000.2954
Remediation & Mitigation
0/8
Schedule — requires maintenance window
0/7

Patching may require device reboot — plan for process interruption

Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later
All products
HOTFIXUpdate Windows 11 Version 24H2 (ARM64) to Build 10.0.26100.9445 or later
HOTFIXUpdate Windows 11 Version 24H2 (x64) to Build 10.0.26100.9445 or later
HOTFIXUpdate Windows 11 Version 25H2 (ARM64) to Build 10.0.26200.9445 or later
HOTFIXUpdate Windows 11 Version 25H2 (x64) to Build 10.0.26200.9445 or later
HOTFIXUpdate Windows 11 Version 26H1 (x64) to Build 10.0.28000.2954 or later
HOTFIXUpdate Windows 11 Version 26H1 (ARM64) to Build 10.0.28000.2954 or later
Long-term hardening
0/1
HARDENINGRestrict local user account access on HMI systems and engineering workstations to only authorized personnel; audit and remove unnecessary local accounts
API: /api/v1/advisories/db7f4217-d5b3-4fa3-8ed5-3548c85a7cc9

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Win32k Elevation of Privilege Vulnerability | CVSS 7.8 - OTPulse