Win32k Information Disclosure Vulnerability

MonitorCVSS 5.5CVE-2026-69609Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

An out-of-bounds read vulnerability in the Windows Win32K graphics kernel allows a local attacker with user-level credentials to read sensitive data from kernel memory. The vulnerability affects Windows 10 (all versions), Windows 11 (all versions), Windows Server 2016, 2019, 2022, and 2025. Exploitation requires the attacker to already have local user access to the system.

What this means
What could happen
An attacker with local access to a Windows machine could read sensitive memory information from the Win32K graphics kernel, potentially exposing credentials or configuration data. The attacker must already have user-level access to the system.
Who's at risk
Windows 10, Windows 11, and Windows Server 2016, 2019, 2022, and 2025 systems, particularly those running HMI software, engineering workstations, or data collectors in water/utility networks. Server Core installations and all processor architectures (32-bit, 64-bit, ARM64) are affected.
How it could be exploited
An attacker with local user credentials could run specially crafted code that triggers an out-of-bounds memory read in the Windows graphics kernel (Win32K). This allows the attacker to leak sensitive information from kernel memory without escalating privileges.
Prerequisites
  • Local user account credentials
  • Ability to execute code on the affected Windows system
  • No special system configuration required
Requires local credentialsLow complexity exploitationAffects Windows infrastructure used in OT networks
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXInstall the September 2026 Windows security update on all Windows 10, Windows 11, and Windows Server 2016/2019/2022/2025 systems
All products
HOTFIXPrioritize patching Windows systems that host engineering workstations, HMI (Human-Machine Interface) servers, or data historian systems
Long-term hardening
0/1
HARDENINGRestrict local login privileges to engineering staff only; disable local interactive logon for service accounts and shared workstations
API: /api/v1/advisories/70dd5642-29ee-4ee4-875c-6ab269e3bc4d

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.