Windows Kernel Elevation of Privilege Vulnerability

Plan PatchCVSS 7.1CVE-2026-69366Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionRequired
Summary

A use-after-free vulnerability in the Windows Kernel allows an authorized user with a valid account on a Windows system to elevate their privileges to system level. The flaw can be exploited over a network by an attacker who has legitimate user credentials. This affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 on both 32-bit and 64-bit architectures.

What this means
What could happen
A logged-in user on a Windows machine could run commands with system-level privileges, potentially allowing them to modify critical applications, access sensitive data, or disable security controls on your network.
Who's at risk
This affects IT administrators, workstation users, and operators of any systems running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025. If your SCADA systems, HMI interfaces, or engineering workstations run Windows Server or Windows 10/11, they are at risk. Any networked Windows machine where staff have user accounts is vulnerable.
How it could be exploited
An attacker with a user account on a Windows workstation or server could trigger a use-after-free flaw in the kernel through a crafted application or network operation. Once exploited, the attacker gains system privileges and can modify configurations, install malware, or alter system behavior without administrative consent.
Prerequisites
  • Valid user account credentials on the affected Windows system
  • Local or network access to the system
  • Ability to execute code or trigger the vulnerable kernel code path
Elevation of privilege via logged-in userAffects multiple Windows versions with widespread deploymentExploitation more likely (per Microsoft assessment)Network-accessible vulnerability
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/4
Do now
0/1
HARDENINGRestrict remote access to Windows servers and workstations to authorized networks only using firewall rules
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXPrioritize patching Windows Server 2019, 2022, and 2025 systems in your critical infrastructure first
All products
HOTFIXApply the 2026-Sep security update for your Windows version
Long-term hardening
0/1
HARDENINGEnforce the principle of least privilege: limit user accounts to the minimum permissions needed for their role
API: /api/v1/advisories/5fefa8ca-796f-4fae-9d16-11b60224f04e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Kernel Elevation of Privilege Vulnerability | CVSS 7.1 - OTPulse