Windows Kernel Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-69466Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

Time-of-check time-of-use (TOCTOU) race condition in the Windows Kernel allows an authorized local attacker to elevate privileges. The vulnerability exists in all affected versions of Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025.

What this means
What could happen
An authorized user on a Windows workstation or server running SCADA client software, HMI, or engineering tools could escalate their privileges to administrator level, gaining control over the device and potentially altering plant operations or accessing sensitive configuration data.
Who's at risk
Windows workstations and servers running SCADA clients, HMI software, or engineering workstations at water utilities and electric utilities. Any operator, engineer, or third-party contractor with local user account access is at risk of escalating to full system control.
How it could be exploited
An attacker with a local user account on the Windows system can exploit a race condition in the Windows Kernel to escalate privileges to SYSTEM or administrator level without additional privileges. This could be an operator, contractor, or compromised staff account with limited initial access.
Prerequisites
  • Local user account on the Windows system
  • Physical or remote desktop access to the machine
  • No special network connectivity required
  • No elevated privileges required initially
Local exploitation only—requires user account on the machineLow complexity attackAffects Windows systems running critical OT softwareAlready being exploited in the wild
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXInstall the September 2026 Windows security update for your Windows version (see affected products list for specific build numbers)
Long-term hardening
0/3
HARDENINGRestrict local login access to Windows machines running engineering or SCADA client software to authorized personnel only
HARDENINGMonitor local privilege escalation attempts via Windows Event Viewer (Event ID 4672 for special privileges)
HARDENINGEnforce multi-factor authentication or strong password policies for all local accounts
API: /api/v1/advisories/9903a42b-97a7-4831-81d1-7189c3f00f41

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Kernel Elevation of Privilege Vulnerability | CVSS 7 - OTPulse