Windows Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 7.1CVE-2026-69706Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionRequired
Summary

A use-after-free vulnerability in Windows Win32k (the kernel-mode graphics and windowing subsystem) allows an authorized user to elevate privileges to system level. The flaw exists in memory management within the windowing subsystem and can be triggered through specific user interactions with specially crafted applications. Affected versions span Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64, and ARM64 architectures. Microsoft has released patches for all affected versions.

What this means
What could happen
An attacker with a standard user account on an unpatched Windows machine could exploit a memory management flaw to run code with system-level privileges, potentially allowing them to modify critical control processes or disable monitoring on engineering workstations.
Who's at risk
Windows system administrators responsible for engineering workstations, HMI (Human-Machine Interface) servers, and data historian systems that run on Windows Server or Windows 10/11. This primarily affects utility organizations using Windows-based SCADA software, domain controllers, and edge computing devices for monitoring and control. Server Core installations running Windows Server 2016, 2019, 2022, and 2025 are also affected if used for OT connectivity or historian functions.
How it could be exploited
An attacker needs a local user account on the target Windows machine. They would trigger the use-after-free condition in Win32k (the graphics/windowing subsystem) through a specially crafted application or interaction, causing the kernel to execute attacker-controlled code with elevated privileges. The attack requires user interaction (UI) but can be delivered remotely via phishing or malicious file if combined with other delivery mechanisms.
Prerequisites
  • Local or remote access with a standard (non-admin) user account
  • User interaction required (user must perform an action like clicking or opening a file)
  • Unpatched Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025
Affects widespread Windows infrastructure (Windows 10, 11, Server 2016-2025)Requires low-complexity user interaction to exploitLeads to full system privilege escalationExploitation is less likely but possible (EPSS 0.4%)No authentication bypass required if attacker already has local user access
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/4
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXApply September 2026 Windows security updates to all Windows 10, Windows 11, and Windows Server machines (specific build numbers provided in advisory for each version)
HOTFIXPrioritize patching engineering workstations and any Windows systems that access industrial control networks or process automation software
Long-term hardening
0/2
HARDENINGDisable or restrict unnecessary user applications and restrict user permissions to essential job functions to limit exposure to UI-based exploitation vectors
HARDENINGImplement network segmentation to restrict connectivity between standard workstations and safety-critical OT systems, limiting lateral movement if a workstation is compromised
API: /api/v1/advisories/6d762034-bdef-4b26-bd41-78d991660a7b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.