Windows Kernel Information Disclosure Vulnerability

MonitorCVSS 5.7CVE-2026-69723Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary

A Windows Kernel vulnerability allows an authorized user to read sensitive kernel memory information that is normally restricted. This could expose system configuration details over a network. The vulnerability affects Windows 10, Windows 11, Windows Server 2016 through 2025 across multiple versions and architectures. Exploitation requires a valid user account on the system.

What this means
What could happen
An attacker with user access to a Windows system could read sensitive kernel memory information that is normally restricted, potentially exposing system configuration details or other data needed for further attacks. This is a low-risk vulnerability in most OT environments because it requires user-level access and only discloses information rather than enabling direct control of systems.
Who's at risk
IT managers running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 on any engineering workstations, HMI (human-machine interface) servers, or administrative systems that touch OT networks. This affects both 32-bit and 64-bit systems across multiple Windows versions.
How it could be exploited
An attacker would need a valid user account on the system (or ability to trick a user into running code). Once logged in, they can read protected kernel memory to extract sensitive information. The attack requires user interaction or prior compromise to gain initial access.
Prerequisites
  • Valid user account on the affected Windows system or ability to execute code as a user
  • Local or remote network access to the system
Requires authentication (user account access)Low exploit probability (1.0% EPSS)Not actively exploited (not KEV)Medium severity information disclosure
Exploitability
Unlikely to be exploited — EPSS score 1.0%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Sep Windows security update to all affected systems (see product fixes for build numbers matching your Windows version)
Long-term hardening
0/2
HARDENINGRestrict user accounts to only necessary privileges; remove unnecessary local admin rights from standard user accounts
HARDENINGEnforce group policy to limit who can log in to sensitive systems running SCADA interfaces or engineering workstations
API: /api/v1/advisories/aec1f7c4-1143-4b29-b8bc-4a8c0df2cb5b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.