Windows Kernel Elevation of Privilege Vulnerability
Plan PatchCVSS 7.1CVE-2026-69366Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionRequired
Summary
A use-after-free vulnerability in the Windows Kernel allows an authorized user with a valid account on a Windows system to elevate their privileges to system level. The flaw can be exploited over a network by an attacker who has legitimate user credentials. This affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 on both 32-bit and 64-bit architectures.
What this means
What could happen
A logged-in user on a Windows machine could run commands with system-level privileges, potentially allowing them to modify critical applications, access sensitive data, or disable security controls on your network.
Who's at risk
This affects IT administrators, workstation users, and operators of any systems running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025. If your SCADA systems, HMI interfaces, or engineering workstations run Windows Server or Windows 10/11, they are at risk. Any networked Windows machine where staff have user accounts is vulnerable.
How it could be exploited
An attacker with a user account on a Windows workstation or server could trigger a use-after-free flaw in the kernel through a crafted application or network operation. Once exploited, the attacker gains system privileges and can modify configurations, install malware, or alter system behavior without administrative consent.
Prerequisites
- Valid user account credentials on the affected Windows system
- Local or network access to the system
- Ability to execute code or trigger the vulnerable kernel code path
Elevation of privilege via logged-in userAffects multiple Windows versions with widespread deploymentExploitation more likely (per Microsoft assessment)Network-accessible vulnerability
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/1HARDENINGRestrict remote access to Windows servers and workstations to authorized networks only using firewall rules
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXPrioritize patching Windows Server 2019, 2022, and 2025 systems in your critical infrastructure first
All products
HOTFIXApply the 2026-Sep security update for your Windows version
Long-term hardening
0/1HARDENINGEnforce the principle of least privilege: limit user accounts to the minimum permissions needed for their role
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/5fefa8ca-796f-4fae-9d16-11b60224f04eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.