Windows TCP/IP Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-69385Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A race condition in the Windows TCP/IP kernel allows an authorized local user to elevate privileges to administrator level. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server 2016, 2019, 2022, and 2025. Microsoft has released vendor patches in the September 2026 security update for all affected versions.

What this means
What could happen
An authorized user on a Windows computer or server could exploit this TCP/IP race condition to gain administrative privileges, potentially allowing them to modify control logic, disable alarms, or stop critical processes on any attached OT equipment.
Who's at risk
Windows server and desktop systems used as engineering workstations, HMI hosts, or supervisory computers in water treatment, electric utility, and manufacturing control environments. Particular concern for Windows Server 2016/2019/2022 systems running SCADA software or OPC servers.
How it could be exploited
An attacker with a local login account on a Windows PC or server running vulnerable TCP/IP stack code could trigger a race condition in the networking kernel to escalate from normal user privileges to administrator. Once elevated, they could access OT software or devices connected to that machine via engineering workstations or administrative tools.
Prerequisites
  • Local login account on the Windows machine
  • Ability to execute code locally
  • Vulnerable Windows version running (versions listed below)
Locally exploitableRequires authenticated user accessHigh complexity to exploitAffects all Windows versions from Server 2016 to Windows 11No authentication bypass
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict local login access to Windows engineering workstations to authorized personnel only; use role-based access control and audit local administrator accounts
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXPrioritize patching Windows Server 2016, 2019, and 2022 systems used for OT monitoring or engineering workstations where authorized users handle control system access
All products
HOTFIXApply the September 2026 Windows security patch (or latest cumulative update) to all Windows 10, Windows 11, and Windows Server systems in your environment
API: /api/v1/advisories/ebd62a08-4941-4a1d-b8f7-8e388ea409f3

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows TCP/IP Elevation of Privilege Vulnerability | CVSS 7 - OTPulse