Windows Win32k Elevation of Privilege Vulnerability
Plan PatchCVSS 7CVE-2026-69410Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
A use-after-free vulnerability in Windows Win32k (the graphics subsystem kernel component) allows a user with local access to elevate their privileges to administrative level. The vulnerability affects Windows 10 versions 1607 and 1809, and Windows Server 2016 and 2019. Microsoft has released security updates to correct this issue.
What this means
What could happen
A local user on a Windows workstation or server could exploit a flaw in the graphics subsystem to gain administrative privileges, potentially allowing them to install malware, modify control system configurations, or disrupt operations.
Who's at risk
Organizations running Windows 10 (versions 1607 or 1809) or Windows Server 2016/2019 used as HMI (Human Machine Interface) computers, engineering workstations, or data historian servers in water utilities and electric utilities. Any local user on these systems could escalate privileges.
How it could be exploited
An attacker with local access to a Windows 10 or Server 2019/2016 machine would craft a malicious application that triggers a use-after-free condition in the Win32k kernel component, allowing them to execute code with elevated administrative privileges and compromise the system.
Prerequisites
- Local user account or interactive access to the affected Windows system
- Ability to run applications with the user's privilege level
Requires local accessRequires low-privilege user accountUse-after-free kernel vulnerabilityLow EPSS score indicates exploitation less likely
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/5
Schedule — requires maintenance window
0/4Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXUpdate Windows Server 2019 systems to Build 10.0.17763.9245 or later
Windows Server 2016
HOTFIXUpdate Windows Server 2016 systems to Build 10.0.14393.9512 or later
All products
HOTFIXUpdate Windows 10 Version 1809 systems to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 1607 systems to Build 10.0.14393.9512 or later
Long-term hardening
0/1HARDENINGRestrict local login to workstations and servers to authorized personnel only
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/3d065837-aeab-45a0-8eef-acfe40a63cf1Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.