Windows Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 8CVE-2026-69762Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary

A stack-based buffer overflow in Windows Win32K graphics driver allows an authorized user to elevate privileges and gain system-level access. The vulnerability exists in Windows 10 (versions 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2019, Windows Server 2022, and Windows Server 2025. Microsoft has released patches in the September 2026 security update.

What this means
What could happen
An attacker with a valid user account could exploit a flaw in Windows graphics processing to run commands with system-level privileges, potentially taking full control of the computer or compromising data on it.
Who's at risk
Windows administrators and IT teams managing Windows 10, Windows 11, Windows Server 2019, Windows Server 2022, and Windows Server 2025 systems. This affects engineering workstations, HMI (human-machine interface) systems, and any SCADA/ICS operator consoles running Windows, as well as IT infrastructure servers in critical facilities.
How it could be exploited
An attacker with valid credentials logs into a Windows machine and sends specially crafted input to the Win32k graphics driver. The driver fails to properly validate the input, causing a buffer overflow that allows the attacker to execute code with elevated system privileges.
Prerequisites
  • Valid Windows user account credentials
  • Local or remote network access to the affected Windows system
  • User interaction or ability to trigger graphics processing
Remotely exploitableValid user credentials requiredCould enable full system compromiseAffects engineering and administrative systems in utilities
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (22)
22 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/4
Do now
0/1
HARDENINGEnable network-level authentication (NLA) on Remote Desktop to prevent unauthenticated connections
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXInstall the September 2026 Windows security update on all Windows Server 2019, 2022, and 2025 systems
All products
HOTFIXInstall the September 2026 Windows security update on all affected Windows 10 and Windows 11 systems
Long-term hardening
0/1
HARDENINGRestrict local interactive access to Windows systems to trusted administrators only
API: /api/v1/advisories/b5ec5b14-7fc4-4647-8a58-4997afd648d3

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Win32k Elevation of Privilege Vulnerability | CVSS 8 - OTPulse