Windows Kernel Elevation of Privilege Vulnerability
Plan PatchCVSS 7CVE-2026-69466Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
Time-of-check time-of-use (TOCTOU) race condition in the Windows Kernel allows an authorized local attacker to elevate privileges. The vulnerability exists in all affected versions of Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025.
What this means
What could happen
An authorized user on a Windows workstation or server running SCADA client software, HMI, or engineering tools could escalate their privileges to administrator level, gaining control over the device and potentially altering plant operations or accessing sensitive configuration data.
Who's at risk
Windows workstations and servers running SCADA clients, HMI software, or engineering workstations at water utilities and electric utilities. Any operator, engineer, or third-party contractor with local user account access is at risk of escalating to full system control.
How it could be exploited
An attacker with a local user account on the Windows system can exploit a race condition in the Windows Kernel to escalate privileges to SYSTEM or administrator level without additional privileges. This could be an operator, contractor, or compromised staff account with limited initial access.
Prerequisites
- Local user account on the Windows system
- Physical or remote desktop access to the machine
- No special network connectivity required
- No elevated privileges required initially
Local exploitation only—requires user account on the machineLow complexity attackAffects Windows systems running critical OT softwareAlready being exploited in the wild
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXInstall the September 2026 Windows security update for your Windows version (see affected products list for specific build numbers)
Long-term hardening
0/3HARDENINGRestrict local login access to Windows machines running engineering or SCADA client software to authorized personnel only
HARDENINGMonitor local privilege escalation attempts via Windows Event Viewer (Event ID 4672 for special privileges)
HARDENINGEnforce multi-factor authentication or strong password policies for all local accounts
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/9903a42b-97a7-4831-81d1-7189c3f00f41Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.