Windows Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 8CVE-2026-69689Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary

An out-of-bounds read vulnerability exists in Windows Win32k (the graphics and window management kernel subsystem). An attacker with standard user credentials could exploit this flaw to read memory outside of intended bounds, potentially leading to privilege escalation to SYSTEM level. The vulnerability affects multiple Windows 10 versions, Windows 11, Windows Server 2019, 2022, and 2025 across all supported architectures (32-bit, x64, ARM64). Microsoft has released patches in the September 2026 security update with specific build numbers for each Windows version.

What this means
What could happen
An attacker with standard user credentials could read memory outside of intended bounds in the Windows graphics kernel, potentially escalating to system-level privileges. This could allow them to take complete control of an engineering workstation or HMI running on affected Windows systems.
Who's at risk
Windows 10 and Windows 11 systems running any version (1809, 21H2, 22H2, 23H2, 24H2, 25H2, 26H1), Windows Server 2019, 2022, and 2025 systems. This affects all engineering workstations, HMI platforms, data logging servers, and administrative machines in water and electric utilities that run Windows operating systems. Both 32-bit, x64, and ARM64 architectures are affected.
How it could be exploited
An attacker would need to interact with a user on an affected Windows system who is logged in with standard (non-admin) credentials. The attacker could send a specially crafted request that triggers an out-of-bounds read in Win32k (the Windows graphics and kernel subsystem). If successful, this could expose kernel memory or allow privilege escalation to SYSTEM level, giving the attacker full control over the machine.
Prerequisites
  • Standard user credentials (not admin)
  • Interactive access to an affected Windows system or ability to interact with a logged-in user
  • User interaction with attacker-supplied content
remotely exploitablerequires user interactionrequires valid credentialsaffects Windows systems used in operational environmentsout-of-bounds memory read can lead to privilege escalation
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (22)
22 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/8
Schedule — requires maintenance window
0/7

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXFor Windows Server 2019 and Server Core, update to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXFor Windows Server 2022 and Server Core, update to Build 10.0.20348.5622 or later
All products
HOTFIXApply the September 2026 Windows security update to all affected Windows 10 and Windows Server systems
HOTFIXFor Windows 10 Version 1809 (32-bit and x64), update to Build 10.0.17763.9245 or later
HOTFIXFor Windows 10 Version 21H2 (all architectures), update to Build 10.0.19044.7725 or later
HOTFIXFor Windows 10 Version 22H2 (all architectures), update to Build 10.0.19045.7725 or later
HOTFIXFor Windows 11 all versions, apply the corresponding security update to reach the specified build numbers
Long-term hardening
0/1
HARDENINGRestrict user account privileges on engineering workstations and HMI systems to the minimum required for job functions
API: /api/v1/advisories/25132b42-3645-43f1-89ef-f9abae78fba6

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Win32k Elevation of Privilege Vulnerability | CVSS 8 - OTPulse