Windows Win32k Elevation of Privilege Vulnerability
Plan PatchCVSS 7CVE-2026-69630Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
A flaw in Windows Win32k kernel-mode driver allows an out-of-bounds memory read. An authorized local user can exploit this to read sensitive kernel memory and escalate privileges to SYSTEM level. Affected: Windows 10 (builds 1607, 1809, 21H2, 22H2), Windows 11 (builds 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 on all architectures (32-bit, x64, ARM64).
What this means
What could happen
An attacker with local access to a Windows system could exploit an out-of-bounds memory read in the Win32k graphics driver to escalate their privileges from a limited user to full system/administrator control. This could allow unauthorized access to SCADA systems, HMIs, or engineering workstations running on that Windows host.
Who's at risk
Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server (2016, 2019, 2022, 2025) users on engineering workstations, HMI systems, and IT management servers. Any facility using Windows-based SCADA software, plant information management systems (PIMS), or automation engineering tools running these operating systems.
How it could be exploited
An attacker with a local user account executes a specially crafted application that triggers an out-of-bounds read in the Win32k kernel driver. The memory read allows the attacker to leak sensitive kernel information, which is then used to bypass security mechanisms and escalate to SYSTEM privileges. Once escalated, the attacker can install malware, modify system files, or access sensitive industrial control system data and applications.
Prerequisites
- Local user account on the Windows system
- Ability to execute applications or scripts on the machine
- User interaction required: No
- The Win32k kernel component must be loaded (standard on all Windows systems with GUI)
Requires local user account (not unauthenticated)High complexity exploitationAffects core Windows kernel driverImpacts confidentiality, integrity, and availabilityExploitation assessed as unlikely but possible
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply Microsoft's September 2026 security update (Windows Update) to patch CVE-2026-69630
Long-term hardening
0/2HARDENINGRestrict user account control on engineering workstations and SCADA servers—disable accounts that do not require interactive login
HARDENINGEnable Windows Defender Exploit Guard to mitigate kernel-mode vulnerability exploitation
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/9f60e4ac-0528-46ae-a322-670d9ca66b44Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.