Windows Win32k Elevation of Privilege Vulnerability
Plan PatchCVSS 7CVE-2026-69610Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
A buffer over-read vulnerability in Windows Win32K graphics subsystem allows an authorized local user to escalate privileges from standard user to administrative level. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server (2016, 2019, 2022, 2025). Microsoft has issued patches in the 2026-Sep security update for all affected versions.
What this means
What could happen
A user with local access to a Windows machine can exploit a buffer over-read flaw in the graphics system to gain administrative privileges, potentially allowing them to modify HMI software, PLC configurations, or other critical control system applications.
Who's at risk
IT staff, engineering workstations running Windows 10 or Windows Server (2016 and later), and any HMI or engineering software running on Windows systems in your control network. This primarily affects staff who log into these machines locally or via remote sessions.
How it could be exploited
An attacker who already has a local user account on a Windows workstation or server exploits the Win32K buffer over-read vulnerability to escalate to administrative privileges. This could be leveraged to modify engineering software, compromise the integrity of control logic, or install persistence mechanisms on critical machines.
Prerequisites
- Local user account on an affected Windows system
- No additional authentication required beyond standard user login
- Access to the affected Windows system (physical or remote desktop session)
Low complexity attackLocal access required (not remotely exploitable)Requires valid user credentialsAffects all Windows versions
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/8
Schedule — requires maintenance window
0/7Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9512 or later
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5622 or later
All products
HOTFIXUpdate Windows 10 Version 1809 to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 21H2 to Build 10.0.19044.7725 or later
HOTFIXUpdate Windows 10 Version 22H2 to Build 10.0.19045.7725 or later
HOTFIXUpdate Windows 11 (all versions) to the specified 2026-Sep security update versions
Long-term hardening
0/1HARDENINGRestrict local user account provisioning on engineering workstations and servers to authorized personnel only
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/f2232ee4-9139-48bd-9cb3-a3a253d7804dGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.