Windows TCP/IP Elevation of Privilege Vulnerability
Plan PatchCVSS 7.1CVE-2026-69757Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionRequired
Summary
A use-after-free vulnerability in Windows TCP/IP stack allows an authorized attacker to elevate privileges on affected systems. The vulnerability exists in Windows 10 (all versions 1809, 21H2, 22H2), Windows 11 (all recent versions), Windows Server 2019, Windows Server 2022, and Windows Server 2025 across all supported architectures. Exploitation requires valid user credentials on the target system and can result in system-level code execution.
What this means
What could happen
A user with local access to a Windows machine running affected versions can exploit this TCP/IP flaw to gain system-level privileges, potentially giving an attacker full control of the computer. This could affect engineering workstations, SCADA servers, or any Windows-based control system on your network.
Who's at risk
Windows 10, Windows 11, Windows Server 2019, Windows Server 2022, and Windows Server 2025 systems running on all architectures (32-bit, x64, ARM64). This affects any IT infrastructure running these operating systems, including engineering workstations, HMI servers, data historians, and domain controllers that may interact with OT networks.
How it could be exploited
An attacker with a valid user account on a Windows machine sends specially crafted TCP/IP packets over the network to trigger a use-after-free condition in the TCP/IP stack. This memory corruption allows the attacker to execute code with elevated (SYSTEM) privileges. The attacker needs to be already authenticated to the system or have convinced a user to interact with a malicious network stimulus.
Prerequisites
- Valid user account on the affected Windows system
- Network access to the Windows machine
- User interaction with malicious network stimulus or ability to execute commands as an authenticated user
Remotely exploitableRequires valid user credentialsMedium complexity exploitationHigh impact (privilege escalation)Affects multiple Windows versions widely deployed
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (22)
22 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/10
Schedule — requires maintenance window
0/9Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXUpdate Windows Server 2019 (including Server Core) to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 (including Server Core) to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 (all installations) to Build 10.0.26100.33438 or later
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit and x64) to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 21H2 (32-bit, ARM64, x64) to Build 10.0.19044.7725 or later
HOTFIXUpdate Windows 10 Version 22H2 (32-bit, ARM64, x64) to Build 10.0.19045.7725 or later
HOTFIXUpdate Windows 11 Version 23H2 (ARM64 and x64) to Build 10.0.22631.7582 or later
HOTFIXUpdate Windows 11 Version 24H2 (ARM64 and x64) to Build 10.0.26100.9445 or later
HOTFIXUpdate Windows 11 Version 25H2 (ARM64 and x64) to Build 10.0.26200.9445 or later
Long-term hardening
0/1HARDENINGLimit local user account creation and restrict which users can log in to critical Windows systems (SCADA servers, engineering workstations) to necessary personnel only
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/53ed3182-db4c-4101-8c2c-8bf3ccea6794Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.